Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

DerBiz Strikes Again[CLOSED]


  • This topic is locked This topic is locked

#1
paradox99

paradox99

    New Member

  • Member
  • Pip
  • 4 posts
I've been trying to get rid of DerBiz from going though other forum posts but the HJT log is slightly different in every case. Like some others it only appeared on my system after my gf downloaded a newer version of MSN Messenger. Ive tried the steps you suggest but come unstuck when running Ad-Adware as my system auto shuts down due to something happening in the RPC registry.

Here's My HJT Log I've run CWShredder just prior to getting the log if that affects it.

Logfile of HijackThis v1.99.1
Scan saved at 15:57:19, on 14/05/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\videosd32.exe
C:\WINDOWS\System32\dllmanager.exe
C:\WINDOWS\System32\scvhosting.exe
C:\WINDOWS\System32\Ndisxp.exe
C:\WINDOWS\System32\mstaskman.exe
C:\WINDOWS\System32\msc32.exe
C:\TBC.exe
C:\WINDOWS\System32\navprotect.exe
C:\WINDOWS\System32\winlite.exe
C:\WINDOWS\System32\mcafee32.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\WINDOWS\System32\hzbgnegxo.exe
C:\WINDOWS\System32\spools.exe
C:\WINDOWS\System32\winsysi.exe
C:\WINDOWS\System32\ati2vid.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\Program Files\Wcnv\Liacx.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\aclfmon.exe
C:\WINDOWS\System32\scrtkfg.exe
C:\WINDOWS\System32\ziptcomm.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Steve Binns\My Documents\fix software\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://community.derbiz.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.freeserve.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://format.packar...hase=6&key=OEM4
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Freeserve
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [msnmsg] C:\TBC.exe
O4 - HKLM\..\Run: [Windows Monitor] winmon.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\Run: [PPPOEOE] winlite.exe
O4 - HKLM\..\Run: [McAfee Windows Protection] mcafee32.exe
O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\Run: [dlite] dllmanager.exe
O4 - HKLM\..\Run: [starter] scvhosting.exe
O4 - HKLM\..\Run: [NvCplScan] msc32.exe
O4 - HKLM\..\Run: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\Run: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\Run: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKLM\..\Run: [Print Spooler] spools.exe
O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Esobhyi] C:\Program Files\Wcnv\Liacx.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [sFmO3qW] aclfmon.exe
O4 - HKLM\..\Run: [System CSRSS Patch] scrtkfg.exe
O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\RunServices: [Print Spooler] spools.exe
O4 - HKLM\..\RunServices: [MSVsm] rpcxcntrx.exe
O4 - HKLM\..\RunServices: [MSVsmt] rpcxctx.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunServices: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKLM\..\RunServices: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\RunServices: [system] system32.exe
O4 - HKLM\..\RunServices: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\RunServices: [Microsoft WinUpdates] serm32.exe
O4 - HKLM\..\RunServices: [dlite] dllmanager.exe
O4 - HKLM\..\RunServices: [Windows Monitor] winmon.exe
O4 - HKLM\..\RunServices: [Microsoft media] winmplayers.exe
O4 - HKLM\..\RunServices: [starter] scvhosting.exe
O4 - HKLM\..\RunServices: [NvCplScan] msc32.exe
O4 - HKLM\..\RunServices: [winmgr.exe] scvhost.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [McAfee Windows Protection] mcafee32.exe
O4 - HKLM\..\RunServices: [PPPOEOE] winlite.exe
O4 - HKLM\..\RunServices: [System CSRSS Patch] scrtkfg.exe
O4 - HKLM\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunOnce: [dlite] dllmanager.exe
O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
O4 - HKLM\..\RunOnce: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\RunOnce: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\RunOnce: [NvCplScan] msc32.exe
O4 - HKCU\..\Run: [Windows Monitor] winmon.exe
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [McAfee Windows Protection] mcafee32.exe
O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\Run: [dlite] dllmanager.exe
O4 - HKCU\..\Run: [starter] scvhosting.exe
O4 - HKCU\..\Run: [NvCplScan] msc32.exe
O4 - HKCU\..\Run: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKCU\..\Run: [MS Task Manager Setup] mstaskman.exe
O4 - HKCU\..\Run: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKCU\..\Run: [Print Spooler] spools.exe
O4 - HKCU\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [do5ERkanh] ziptcomm.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunServices: [Windows Monitor] winmon.exe
O4 - HKCU\..\RunOnce: [dlite] dllmanager.exe
O4 - HKCU\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\RunOnce: [NvCplScan] msc32.exe
O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
O4 - HKCU\..\RunOnce: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKCU\..\RunOnce: [MS Task Manager Setup] mstaskman.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O14 - IERESET.INF: START_PAGE_URL=http://www.freeserve.com/
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.8.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1099959988099
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comne...iveSecurity.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda....c18/games10.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://217.73.66.1/del/loader.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pdownloader.cab
O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Hklnkc32.dll
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe

Thanks for your time all help will be greatly appreciated

Paradox99
  • 0

Advertisements


#2
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi paradox99

Please read through the instructions before you start (you may want to print this out).

Download CWShredder (there is a link in my signature), unzip it, and save it on the Desktop. Please do not run it yet, though.

Please set your system to show all files; please see here if you're unsure how to do this.

Lets see if this will finds any hidden Trojan’s http://www.ewido.net/en/download/
This setup contains the free as well as the plus-version of the ewido security suite. After the installation, a free 14-day test version containing all the extensions of the plus-version will be activated. At the end of the test phase, the extensions of the plus version are deactivated and the freeware version can be used unlimited times. The purchased license code of the plus version can be entered at any time.
Ewido will auto-udate. Don't run it yet

Reboot into Safe Mode: please see here if you are not sure how to do this.

Run CWShredder to fix your CWS problem.

Run ewido full scan save the log when the scan has finnished.

Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://community.derbiz.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:\WINDOWS\wsem303.dll
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O4 - HKLM\..\Run: [msnmsg] C:\TBC.exe
O4 - HKLM\..\Run: [Windows Monitor] winmon.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\Run: [PPPOEOE] winlite.exe
O4 - HKLM\..\Run: [McAfee Windows Protection] mcafee32.exe
O4 - HKLM\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\Run: [dlite] dllmanager.exe
O4 - HKLM\..\Run: [starter] scvhosting.exe
O4 - HKLM\..\Run: [NvCplScan] msc32.exe
O4 - HKLM\..\Run: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\Run: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\Run: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKLM\..\Run: [Print Spooler] spools.exe
O4 - HKLM\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [Esobhyi] C:\Program Files\Wcnv\Liacx.exe
O4 - HKLM\..\Run: [sFmO3qW] aclfmon.exe
O4 - HKLM\..\Run: [System CSRSS Patch] scrtkfg.exe
O4 - HKLM\..\RunServices: [WindowsRegKeys update] winsysi.exe
O4 - HKLM\..\RunServices: [Print Spooler] spools.exe
O4 - HKLM\..\RunServices: [MSVsm] rpcxcntrx.exe
O4 - HKLM\..\RunServices: [MSVsmt] rpcxctx.exe
O4 - HKLM\..\RunServices: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKLM\..\RunServices: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunServices: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKLM\..\RunServices: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\RunServices: [system] system32.exe
O4 - HKLM\..\RunServices: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\RunServices: [Microsoft WinUpdates] serm32.exe
O4 - HKLM\..\RunServices: [dlite] dllmanager.exe
O4 - HKLM\..\RunServices: [Windows Monitor] winmon.exe
O4 - HKLM\..\RunServices: [Microsoft media] winmplayers.exe
O4 - HKLM\..\RunServices: [starter] scvhosting.exe
O4 - HKLM\..\RunServices: [NvCplScan] msc32.exe
O4 - HKLM\..\RunServices: [winmgr.exe] scvhost.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [McAfee Windows Protection] mcafee32.exe
O4 - HKLM\..\RunServices: [PPPOEOE] winlite.exe
O4 - HKLM\..\RunServices: [System CSRSS Patch] scrtkfg.exe
O4 - HKLM\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKLM\..\RunOnce: [dlite] dllmanager.exe
O4 - HKLM\..\RunOnce: [starter] scvhosting.exe
O4 - HKLM\..\RunOnce: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKLM\..\RunOnce: [MS Task Manager Setup] mstaskman.exe
O4 - HKLM\..\RunOnce: [NvCplScan] msc32.exe
O4 - HKCU\..\Run: [Windows Monitor] winmon.exe
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [McAfee Windows Protection] mcafee32.exe
O4 - HKCU\..\Run: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\Run: [dlite] dllmanager.exe
O4 - HKCU\..\Run: [starter] scvhosting.exe
O4 - HKCU\..\Run: [NvCplScan] msc32.exe
O4 - HKCU\..\Run: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKCU\..\Run: [MS Task Manager Setup] mstaskman.exe
O4 - HKCU\..\Run: [WindowsRegKey upd4te2d4te] hzbgnegxo.exe
O4 - HKCU\..\Run: [Print Spooler] spools.exe
O4 - HKCU\..\Run: [WindowsRegKeys update] winsysi.exe
O4 - HKCU\..\Run: [ATI VIDEO REGKEY] ati2vid.exe
O4 - HKCU\..\Run: [do5ERkanh] ziptcomm.exe
O4 - HKCU\..\RunServices: [Windows Monitor] winmon.exe
O4 - HKCU\..\RunOnce: [dlite] dllmanager.exe
O4 - HKCU\..\RunOnce: [Win32 Configuration] videosd32.exe
O4 - HKCU\..\RunOnce: [NvCplScan] msc32.exe
O4 - HKCU\..\RunOnce: [starter] scvhosting.exe
O4 - HKCU\..\RunOnce: [Win32 NDIS Driver] Ndisxp.exe
O4 - HKCU\..\RunOnce: [MS Task Manager Setup] mstaskman.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup.../bridge-c18.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://imgfarm.com/i...etup1.0.0.8.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comne...iveSecurity.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda....c18/games10.cab
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-downlo...tsInstaller.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://217.73.66.1/del/loader.cab
O21 - SSODL: Web Event Logger - {79FEACFF-FFCE-815E-A900-316290B5B738} - C:\WINDOWS\System32\Hklnkc32.dll
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe
O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe

Click on Fix Checked when finished and exit HijackThis.


Using Windows Explorer, locate the following files/folders, and delete them:
C:\WINDOWS\wsem303.dll<--Delete this file
C:\WINDOWS\System32\msbe.dll<--Delete this file
C:\TBC.exe<--Delete the whole folder
winmon.exe<--Delete this file
navprotect.exe<--Delete this file
winlite.exe<--Delete this file
mcafee32.exe<--Delete this file
videosd32.exe<--Delete this file
dllmanager.exe<--Delete this file
scvhosting.exe<--Delete this file
msc32.exe<--Delete this file
Ndisxp.exe<--Delete this file
mstaskman.exe<--Delete this file
hzbgnegxo.exe<--Delete this file
spools.exe<--Delete this file
winsysi.exe<--Delete this file
ati2vid.exe<--Delete this file
C:\Program Files\Internet Optimizer<--Delete the whole folder
C:\Program Files\BullsEye Network<--Delete the whole folder
C:\Program Files\AutoUpdate<--Delete the whole folder
C:\Program Files\Wcnv<--Delete the whole folder
aclfmon.exe<--Delete this file
scrtkfg.exe<--Delete this file
rpcxcntrx.exe<--Delete this file
system32.exe<--Delete this file
serm32.exe<--Delete this file
winmplayers.exe<--Delete this file
scvhost.exe<--Delete this file
ziptcomm.exe<--Delete this file
C:\WINDOWS\web\related.htm<--Delete this file
C:\WINDOWS\System32\Hklnkc32.dll<--Delete this file
C:\WINDOWS\System32\hwclock.exe<--Delete this file
C:\WINDOWS\zeta.exe<--Delete this file
Exit Explorer.

If you were unable to find any of the files then please follow these additional instructions:
Download Pocket Killbox and unzip it; save it to your Desktop.
Run killbox and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes. Let the system reboot.

Reboot as normal.

Please download, install and run this disk cleanup utility called Cleanup version 4.0!
http://downloads.ste...p/CleanUp40.exe
It will get rid of any malware which may be hiding in your temp folders ( a common hiding place). You will also regain a massive amount of disk space. Here is a tutorial which describes its usage:
http://www.bleepingc...tutorial93.html
Check the custom settings to your liking under options, but be sure to delete temporary files and temporary internet files for all user profiles. Also, cleanout the prefetch folder and the recycle bin.
Reboot when prompted to let it clean out the remaining files.

Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
http://housecall.tre.../start_corp.asp
Please post the logs From Panda virus scan and HJT.logWe will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#3
paradox99

paradox99

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Hi,

Done as you asked, had some problems with ewido crashing right at the end due to a corupt file but rebooting and letting the system run a scan disck deleted the corupt file. Here is the panda log:


Incident Status Location

Adware:Adware/Ucmore No disinfected C:\WINDOWS\ucmoreiex.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall*.exe
Adware:Adware/SaveNow No disinfected Windows Registry
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network
Adware:Adware/Gator No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\Program Files\180solutions
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer
Spyware:Spyware/ISTbar No disinfected C:\Program Files\ISTbar
Adware:Adware/PurityScan No disinfected Windows Registry
Adware:Adware/PortalScan No disinfected C:\WINDOWS\System32\swin32.dll
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan
Adware:Adware/SAHAgent No disinfected Windows Registry
Adware:Adware/FunWeb No disinfected C:\Program Files\FunWebProducts
Adware:Adware/BHO No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\Program Files\AutoUpdate
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.???
Adware:Adware/WebHancer No disinfected C:\Program Files\webHancer
Adware:Adware/MediaTickets No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\alchem.???
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind
Adware:Adware/AdLogix No disinfected C:\WINDOWS\System32\adupdmanager.xml
Adware:Adware/TopRebates No disinfected C:\temp\WebRebates*.exe
Adware:Adware/Twain-Tech No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\THI*.tmp
Adware:Adware/WUpd No disinfected C:\Program Files\Windows SyncroAd
Adware:Adware/EliteBar No disinfected Windows Registry
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\System32\exdl.exe
Spyware:Spyware/MarketScore No disinfected C:\WINDOWS\System32\OSSProxy.exe
Adware:Adware/WhenUSearch No disinfected Windows Registry
Adware:Adware/MyWebSearch No disinfected C:\Program Files\MyWebSearch
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Adware:Adware/TopConvert No disinfected Windows Registry
Adware:Adware/Transponder No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\dummy.htm
Virus:Trj/Downloader.ALQ Disinfected Operating system
Adware:Adware/IPBill No disinfected C:\WINDOWS\System32\comload.dll
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\Protector.exe
Virus:Trj/Downloader.BWL Disinfected Operating system
Adware:Adware/WinAD No disinfected C:\clearlogs.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\180SAInstaller.exe
Adware:Adware/Envolo No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\AutoUpdate0\setup.inf
Adware:Adware/nCase No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\Del28.tmp
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\kvbyjum.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\nvrwkh.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ph.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\pm.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ProxyStub.dll
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temporary Internet Files\Content.IE5\9S8LJZ9D\agobot3[1].exe
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.inf]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.exe]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.ini]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.ini
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\baaufkd.exe
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.ini
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\cuujibkf.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\fpdqzcox.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\kbzmny.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\pbjlpum.exe
Virus:Trj/Downloader.GK Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\polmx.cab
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\riecrhfl.exe
Virus:Trj/Downloader.TC Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\Temporary Internet Files\Content.IE5\28Z0K23C\T[1].html
Spyware:Spyware/LocalNRD No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI128D.tmp\localNrd.inf
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[twaintec.dll]
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[preInsTT.exe]
Virus:Trj/Downloader.NG Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[polall1m.exe]
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\uzyubix.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\vkihcv.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\yyurlfow.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-291.dll
Adware:Adware/WinAD No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-652.dll
Adware:Adware/FunWeb No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-691.inf
Adware:Adware/MediaTickets No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.dll
Adware:Adware/MediaTickets No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.inf
Virus:Trj/Downloader.BPY Disinfected C:\Documents and Settings\Steve Binns\My Documents\New Kit\cleanreg.exe
Virus:W32/Gaobot.CLD.worm Disinfected C:\jwnrvuhm.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\bargains.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\Uninstall.exe
Adware:Adware/Apropos No disinfected C:\Program Files\CxtPls\ProxyStub.dll
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\optimize.exe
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\update\optimize313.exe
Virus:Trj/Multidropper.TY Disinfected C:\temp\Bargains.exe
Adware:Adware/nCase No disinfected C:\temp\msbbhook.dll
Adware:Adware/nCase No disinfected C:\temp\NCasePackage.exe
Adware:Adware/SAHAgent No disinfected C:\temp\sahagent.exe
Adware:Adware/SAHAgent No disinfected C:\temp\SAHPackage.exe
Adware:Adware/nCase No disinfected C:\temp\salm.exe
Adware:Adware/nCase No disinfected C:\temp\salm.log
Adware:Adware/TopRebates No disinfected C:\temp\WebRebates_Auto_InstallSilent_Euro.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\cxtpls_loader.exe
Virus:Trj/Downloader.AHJ Disinfected C:\WINDOWS\Downloaded Program Files\220834__.exe536
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\abasa5jrp_.exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\Downloaded Program Files\ActiveX.inf
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.dll
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\jao.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\lkir8l2gm_.dll
Adware:Adware/WinAD No disinfected C:\WINDOWS\Downloaded Program Files\MediaAccX.dll
Adware:Adware/WUpd No disinfected C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\u6f6uftuc_.exe
Virus:Trj/Downloader.QV Disinfected C:\WINDOWS\Downloaded Program Files\vxiewer.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log-old.log
Adware:Adware/Fastvideoplayer No disinfected C:\WINDOWS\inf\fastvideoplayer.inf
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\installer_SIAC.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall6_30.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall6_38.exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\optimize.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\protector.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\protector_update.exe
Virus:Bck/Webdor.G Disinfected C:\WINDOWS\shch.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\sideb.exe
Virus:W32/Dedler.AJ.worm Disinfected C:\WINDOWS\system\mssecure.exe
Virus:Bck/Small.HI Disinfected C:\WINDOWS\system32\.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\system32\adupdmanager.xml
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\angelex.exe
Virus:W32/Sdbot.AIM.worm Disinfected C:\WINDOWS\system32\ati2vid.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\system32\automove.exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\system32\auto_update_uninstall.exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\system32\auto_update_uninstall.log
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\bbchk.exe
Virus:W32/Sasser.ftp Disinfected C:\WINDOWS\system32\cmd.ftp
Adware:Adware/IPBill No disinfected C:\WINDOWS\system32\comload.dll
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\actalert[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bb[1].exe
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[bridge.dll]
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[jao.dll]
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlogs[1].rar
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlog[1].rar
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\istsvc[1].exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\mine[1].html
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\sfbho13[1].dll
Virus:Trojan Horse Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\test[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\x[1].exe
Virus:W32/Korgo.O.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\x[2].exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\clearlog[1].rar
Virus:Trj/Downloader.BKB Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ftch32d[1].exe
Virus:Trj/Downloader.TA Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ie[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\istdownload[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mine[1].html
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mtrslib2[1].js
Adware:Adware/Zango No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ncase_new[1].exe
Adware:Adware/PowerScan No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\powerscan[1].exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\T[1].html
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab[istactivex.dll]
Virus:Trj/Small.AP Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\boz[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\indexx[1].html
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\istrecover[1].exe
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[1].gif
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[2].gif
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[3].gif
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\nem220[1].dll
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\sidefind13[1].dll
Adware:Adware/TopRebates No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\webrebates_europe[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\x[1].exe
Virus:Trj/Small.AK Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\b0z[1].exe
Virus:W32/Gaobot.CLD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\bot[1].exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\clearlog[1].rar
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[1].exe
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[2].exe
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[3].exe
Virus:Trj/Downloader.TA Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\ie[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\istbar_mainstream[1].dll
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\sidefind[1].exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\wsem303[1].dll
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[2].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[3].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[4].exe
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\eliteapo32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\eliteaye32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitebdi32.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\elitebwr32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitecup32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\eliteevl32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitefbh32.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\eliteggb32.exe
  • 0

#4
paradox99

paradox99

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Hi,

Done as you asked, had some problems with ewido crashing right at the end due to a corupt file but rebooting and letting the system run a scan disck deleted the corupt file. Here is the panda log:


Incident Status Location

Adware:Adware/Ucmore No disinfected C:\WINDOWS\ucmoreiex.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall*.exe
Adware:Adware/SaveNow No disinfected Windows Registry
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network
Adware:Adware/Gator No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\Program Files\180solutions
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer
Spyware:Spyware/ISTbar No disinfected C:\Program Files\ISTbar
Adware:Adware/PurityScan No disinfected Windows Registry
Adware:Adware/PortalScan No disinfected C:\WINDOWS\System32\swin32.dll
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan
Adware:Adware/SAHAgent No disinfected Windows Registry
Adware:Adware/FunWeb No disinfected C:\Program Files\FunWebProducts
Adware:Adware/BHO No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\Program Files\AutoUpdate
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.???
Adware:Adware/WebHancer No disinfected C:\Program Files\webHancer
Adware:Adware/MediaTickets No disinfected Windows Registry
Adware:Adware/IPInsight No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\alchem.???
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind
Adware:Adware/AdLogix No disinfected C:\WINDOWS\System32\adupdmanager.xml
Adware:Adware/TopRebates No disinfected C:\temp\WebRebates*.exe
Adware:Adware/Twain-Tech No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\THI*.tmp
Adware:Adware/WUpd No disinfected C:\Program Files\Windows SyncroAd
Adware:Adware/EliteBar No disinfected Windows Registry
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\System32\exdl.exe
Spyware:Spyware/MarketScore No disinfected C:\WINDOWS\System32\OSSProxy.exe
Adware:Adware/WhenUSearch No disinfected Windows Registry
Adware:Adware/MyWebSearch No disinfected C:\Program Files\MyWebSearch
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Adware:Adware/TopConvert No disinfected Windows Registry
Adware:Adware/Transponder No disinfected C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\dummy.htm
Virus:Trj/Downloader.ALQ Disinfected Operating system
Adware:Adware/IPBill No disinfected C:\WINDOWS\System32\comload.dll
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\Protector.exe
Virus:Trj/Downloader.BWL Disinfected Operating system
Adware:Adware/WinAD No disinfected C:\clearlogs.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\180SAInstaller.exe
Adware:Adware/Envolo No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\AutoUpdate0\setup.inf
Adware:Adware/nCase No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\Del28.tmp
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\kvbyjum.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\nvrwkh.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ph.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\pm.exe
Adware:Adware/Apropos No disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ProxyStub.dll
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Kylie Cox\Local Settings\Temporary Internet Files\Content.IE5\9S8LJZ9D\agobot3[1].exe
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.inf]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.exe]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.ini]
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.ini
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\baaufkd.exe
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.ini
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\cuujibkf.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\fpdqzcox.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\kbzmny.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\pbjlpum.exe
Virus:Trj/Downloader.GK Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\polmx.cab
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\riecrhfl.exe
Virus:Trj/Downloader.TC Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\Temporary Internet Files\Content.IE5\28Z0K23C\T[1].html
Spyware:Spyware/LocalNRD No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI128D.tmp\localNrd.inf
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[twaintec.dll]
Adware:Adware/Twain-Tech No disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[preInsTT.exe]
Virus:Trj/Downloader.NG Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[polall1m.exe]
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\uzyubix.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\vkihcv.exe
Virus:W32/Gaobot.gen.worm Disinfected C:\Documents and Settings\Steve Binns\Local Settings\Temp\yyurlfow.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-291.dll
Adware:Adware/WinAD No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-652.dll
Adware:Adware/FunWeb No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-691.inf
Adware:Adware/MediaTickets No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.dll
Adware:Adware/MediaTickets No disinfected C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.inf
Virus:Trj/Downloader.BPY Disinfected C:\Documents and Settings\Steve Binns\My Documents\New Kit\cleanreg.exe
Virus:W32/Gaobot.CLD.worm Disinfected C:\jwnrvuhm.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\bargains.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\Uninstall.exe
Adware:Adware/Apropos No disinfected C:\Program Files\CxtPls\ProxyStub.dll
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\optimize.exe
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\update\optimize313.exe
Virus:Trj/Multidropper.TY Disinfected C:\temp\Bargains.exe
Adware:Adware/nCase No disinfected C:\temp\msbbhook.dll
Adware:Adware/nCase No disinfected C:\temp\NCasePackage.exe
Adware:Adware/SAHAgent No disinfected C:\temp\sahagent.exe
Adware:Adware/SAHAgent No disinfected C:\temp\SAHPackage.exe
Adware:Adware/nCase No disinfected C:\temp\salm.exe
Adware:Adware/nCase No disinfected C:\temp\salm.log
Adware:Adware/TopRebates No disinfected C:\temp\WebRebates_Auto_InstallSilent_Euro.exe
Adware:Adware/Apropos No disinfected C:\WINDOWS\cxtpls_loader.exe
Virus:Trj/Downloader.AHJ Disinfected C:\WINDOWS\Downloaded Program Files\220834__.exe536
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\abasa5jrp_.exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\Downloaded Program Files\ActiveX.inf
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.dll
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\bridge.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\Downloaded Program Files\jao.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\lkir8l2gm_.dll
Adware:Adware/WinAD No disinfected C:\WINDOWS\Downloaded Program Files\MediaAccX.dll
Adware:Adware/WUpd No disinfected C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\Downloaded Program Files\u6f6uftuc_.exe
Virus:Trj/Downloader.QV Disinfected C:\WINDOWS\Downloaded Program Files\vxiewer.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorHDPlugin.log-old.log
Adware:Adware/Fastvideoplayer No disinfected C:\WINDOWS\inf\fastvideoplayer.inf
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\installer_SIAC.exe
Adware:Adware/SuperSpider No disinfected C:\WINDOWS\msxmidi.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall6_30.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall6_38.exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\optimize.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\protector.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\protector_update.exe
Virus:Bck/Webdor.G Disinfected C:\WINDOWS\shch.exe
Adware:Adware/EliteBar No disinfected C:\WINDOWS\sideb.exe
Virus:W32/Dedler.AJ.worm Disinfected C:\WINDOWS\system\mssecure.exe
Virus:Bck/Small.HI Disinfected C:\WINDOWS\system32\.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\system32\adupdmanager.xml
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\angelex.exe
Virus:W32/Sdbot.AIM.worm Disinfected C:\WINDOWS\system32\ati2vid.exe
Adware:Adware/AdLogix No disinfected C:\WINDOWS\system32\automove.exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\system32\auto_update_uninstall.exe
Adware:Adware/Envolo No disinfected C:\WINDOWS\system32\auto_update_uninstall.log
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\bbchk.exe
Virus:W32/Sasser.ftp Disinfected C:\WINDOWS\system32\cmd.ftp
Adware:Adware/IPBill No disinfected C:\WINDOWS\system32\comload.dll
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\actalert[1].exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bb[1].exe
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[bridge.dll]
Spyware:Spyware/Bridge No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[jao.dll]
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlogs[1].rar
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlog[1].rar
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\istsvc[1].exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\mine[1].html
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\sfbho13[1].dll
Virus:Trojan Horse Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\test[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\x[1].exe
Virus:W32/Korgo.O.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\x[2].exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\clearlog[1].rar
Virus:Trj/Downloader.BKB Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ftch32d[1].exe
Virus:Trj/Downloader.TA Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ie[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\istdownload[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mine[1].html
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mtrslib2[1].js
Adware:Adware/Zango No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ncase_new[1].exe
Adware:Adware/PowerScan No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\powerscan[1].exe
Adware:Adware/MediaTickets No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\T[1].html
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab[istactivex.dll]
Virus:Trj/Small.AP Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\boz[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\indexx[1].html
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\istrecover[1].exe
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[1].gif
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[2].gif
Virus:Bck/Webber.S Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\kk[3].gif
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\nem220[1].dll
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\sidefind13[1].dll
Adware:Adware/TopRebates No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\webrebates_europe[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\x[1].exe
Virus:Trj/Small.AK Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\b0z[1].exe
Virus:W32/Gaobot.CLD.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\bot[1].exe
Adware:Adware/WUpd No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\clearlog[1].rar
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[1].exe
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[2].exe
Adware:Adware/WinAD No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[3].exe
Virus:Trj/Downloader.TA Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\ie[1].exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\istbar_mainstream[1].dll
Adware:Adware/SideFind No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\sidefind[1].exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\wsem303[1].dll
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[1].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[2].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[3].exe
Virus:W32/Korgo.U.worm Disinfected C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\x[4].exe
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\eliteapo32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\eliteaye32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitebdi32.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\elitebwr32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitecup32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\eliteevl32.exe
Adware:Adware/Startpage.SJ No disinfected C:\WINDOWS\system32\elitefbh32.exe
Adware:Adware/StartPage.DD No disinfected C:\WINDOWS\system32\eliteggb32.exe
  • 0

#5
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi paradox99

Please read through the instructions before you start (you may want to print this out).

Please download and install these programs - don't run them yet!!

Trojan remover tool 1

Kaspersky Worm Removal Tool tool 2

sphjfix tool 3

Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch and delete all the files in that folder.

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:

Reboot into Safe Mode: Click here if you don't know how to do this.

Run tool 1 Ewido save the log post the log with your next post.

Run tool 2 Kaspersky Worm Removal Tool save the log post the log with your next post.

Run tool 3 sphjfix save the log post the log with your next post.

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:

Reboot as normal

Please run the following free, online virus scans.
http://www.pandasoft...n_principal.htm
Please post the logs From Panda virus scan and HJT.log we will need them to remove previous infections that have left files on your system.

Kc :tazz:
  • 0

#6
paradox99

paradox99

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Hi,

Tool 2 from kasper labs is a dead link, are the any others addresses that i can download from??

Cheers
  • 0

#7
Guest_thatman_*

Guest_thatman_*
  • Guest
Hi paradox99

This anti-virus is one of the best but takes some time to do a online scan 3hour at most or you can download a full trial 30 days about 6mb
Kaspersky online beta scanner:
http://www.kaspersky...oduct=161744315

Use windows explorer delete the following folders:
C:\Program Files\BullsEye Network<--Delete the whole folder
C:\Program Files\180solutions<--Delete the whole folder
C:\Program Files\Internet Optimizer<--Delete the whole folder
C:\Program Files\ISTbar<--Delete the whole folder
C:\Program Files\Power Scan<--Delete the whole folder
C:\Program Files\FunWebProducts<--Delete the whole folder
C:\Program Files\AutoUpdate<--Delete the whole folder
C:\Program Files\webHancer<--Delete the whole folder
C:\Program Files\SideFind<--Delete the whole folder
C:\Program Files\MyWebSearch<--Delete the whole folder
C:\Program Files\Windows SyncroAd<--Delete the whole folder
C:\Program Files\Internet Optimizer<--Delete the whole folder
C:\clearlogs.exe<--Delete the whole folder
C:\temp<--Delete the whole folder

Download Pocket Killbox and unzip it; save it to your Desktop.
Run killbox and click the radio button that says Delete a file on reboot.
Copy and Paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in where upon you should answer Yes.
Let the system reboot.
C:\WINDOWS\ucmoreiex.exe
C:\WINDOWS\NDNuninstall*.exe
C:\WINDOWS\System32\swin32.dll
C:\WINDOWS\Downloaded Program Files\bridge.???
C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\alchem.???
C:\WINDOWS\System32\adupdmanager.xml
C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\THI*.tmp
C:\WINDOWS\System32\exdl.exe
C:\WINDOWS\System32\OSSProxy.exe
C:\WINDOWS\msxmidi.exe
C:\DOCUME~1\STEVEB~1\LOCALS~1\Temp\dummy.htm
C:\WINDOWS\System32\comload.dll
C:\WINDOWS\Protector.exe
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\180SAInstaller.exe
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\AutoUpdate0\setup.inf
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\Del28.tmp
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ph.exe
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\pm.exe
C:\Documents and Settings\Kylie Cox\Local Settings\Temp\~apropos0\ProxyStub.dll
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.inf]
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.exe]
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.cab[alchem.ini]
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.inf
C:\Documents and Settings\Steve Binns\Local Settings\Temp\alchem.ini
C:\Documents and Settings\Steve Binns\Local Settings\Temp\baaufkd.exe
C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.inf
C:\Documents and Settings\Steve Binns\Local Settings\Temp\conscorr.ini
C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab
C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[twaintec.dll]
C:\Documents and Settings\Steve Binns\Local Settings\Temp\THI5D6B.tmp\twaintec.cab[preInsTT.exe]
C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-291.dll
C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-652.dll
C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200530-691.inf
C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.dll
C:\Documents and Settings\Steve Binns\My Documents\fix software\backups\backup-20050517-200531-424.inf
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\BullsEye Network\Uninstall.exe
C:\Program Files\CxtPls\ProxyStub.dll
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\Internet Optimizer\update\optimize313.exe
C:\temp\msbbhook.dll
C:\temp\NCasePackage.exe
C:\temp\sahagent.exe
C:\temp\SAHPackage.exe
C:\temp\salm.exe
C:\temp\salm.log
C:\temp\WebRebates_Auto_InstallSilent_Euro.exe
C:\WINDOWS\cxtpls_loader.exe
C:\WINDOWS\Downloaded Program Files\abasa5jrp_.exe
C:\WINDOWS\Downloaded Program Files\ActiveX.inf
C:\WINDOWS\Downloaded Program Files\bridge.dll
C:\WINDOWS\Downloaded Program Files\bridge.inf
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.inf
C:\WINDOWS\Downloaded Program Files\HDPlugin1019.dll
C:\WINDOWS\Downloaded Program Files\jao.dll
C:\WINDOWS\Downloaded Program Files\lkir8l2gm_.dll
C:\WINDOWS\Downloaded Program Files\MediaAccX.dll
C:\WINDOWS\Downloaded Program Files\SyncroAdX.dll
C:\WINDOWS\Downloaded Program Files\u6f6uftuc_.exe
C:\WINDOWS\GatorHDPlugin.log
C:\WINDOWS\GatorHDPlugin.log-old.log
C:\WINDOWS\inf\fastvideoplayer.inf
C:\WINDOWS\installer_SIAC.exe
C:\WINDOWS\msxmidi.exe
C:\WINDOWS\NDNuninstall6_30.exe
C:\WINDOWS\NDNuninstall6_38.exe
C:\WINDOWS\optimize.exe
C:\WINDOWS\protector.exe
C:\WINDOWS\protector_update.exe
C:\WINDOWS\shch.exe
C:\WINDOWS\sideb.exe
C:\WINDOWS\system32\adupdmanager.xml
C:\WINDOWS\system32\angelex.exe
C:\WINDOWS\system32\automove.exe
C:\WINDOWS\system32\auto_update_uninstall.exe
C:\WINDOWS\system32\auto_update_uninstall.log
C:\WINDOWS\system32\bbchk.exe
C:\WINDOWS\system32\comload.dll
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\actalert[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bb[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[bridge.dll]
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\bridge[1].cab[jao.dll]
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlogs[1].rar
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\clearlog[1].rar
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\istsvc[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\mine[1].html
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\452BKPSF\sfbho13[1].dll
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\clearlog[1].rar
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\istdownload[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mine[1].html
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\mtrslib2[1].js
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\ncase_new[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\powerscan[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\698RYDI7\T[1].html
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\0006_regular[2].cab[istactivex.dll]
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\indexx[1].html
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\istrecover[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\nem220[1].dll
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\sidefind13[1].dll
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\KHOFG76B\webrebates_europe[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\clearlog[1].rar
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[2].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\dd[3].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\istbar_mainstream[1].dll
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\sidefind[1].exe
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\W5KDSF23\wsem303[1].dll
C:\WINDOWS\system32\eliteapo32.exe
C:\WINDOWS\system32\eliteaye32.exe
C:\WINDOWS\system32\elitebdi32.exe
C:\WINDOWS\system32\elitebwr32.exe
C:\WINDOWS\system32\elitecup32.exe
C:\WINDOWS\system32\eliteevl32.exe
C:\WINDOWS\system32\elitefbh32.exe
C:\WINDOWS\system32\eliteggb32.exe

Post a anti-virus log and a HJT.log

Kc :tazz:
  • 0

#8
Guest_thatman_*

Guest_thatman_*
  • Guest
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member with address of this thread. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP