Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

MSN Messenger virus... again!


  • Please log in to reply

#1
tkke

tkke

    New Member

  • Member
  • Pip
  • 1 posts
Just as many other poor souls happened to do, I clicked on a link I shouldn't have through MSN messenger. Then the link sent itself to everyone on MY messenger and since then I've been having all sorts of problems with pop ups etc. I've read some of the suggestions you've made to others and have run Hijack, Ad-aware, Trend Micro Internet security and Microworld anti-virus. Trend Micro didn't find anything, Ad-aware found some things and cleaned those up. Below is the log of Hijack:

Logfile of HijackThis v1.99.1
Scan saved at 19:14:37, on 16/05/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Trend Micro\Internet Security\pccguide.exe
C:\Program Files\Trend Micro\Internet Security\PCClient.exe
C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe
C:\WINDOWS\system32\msnxmsgrsc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
C:\Program Files\Trend Micro\Internet Security\tmproxy.exe
C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://community.derbiz.com/
O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar\01.01.1601.0\msgr.en-us.en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security\pccguide.exe"
O4 - HKLM\..\Run: [PCClient.exe] "C:\Program Files\Trend Micro\Internet Security\PCClient.exe"
O4 - HKLM\..\Run: [TM Outbreak Agent] "C:\Program Files\Trend Micro\Internet Security\TMOAgent.exe" /run
O4 - HKLM\..\Run: [strmsnmgrs] msnxmsgrsc.exe
O4 - HKLM\..\Run: [ASDPLUGIN] C:\WINDOWS\system32\uk_nm.exe -N
O4 - HKLM\..\Run: [checkrun] c:\windows\system32\elitecme32.exe
O4 - HKLM\..\RunServices: [strmsnmgrs] msnxmsgrsc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [strmsnmgrs] msnxmsgrsc.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: raid_tool.exe.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...etup1.0.0.8.cab
O16 - DPF: {30CE93AE-4987-483C-9ABE-F2BD5301AB70} - http://64.158.165.49...es/dbaccess.exe
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Personal Firewall (PccPfw) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\PccPfw.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: Trend NT Realtime Service (Tmntsrv) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\Tmntsrv.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Incorporated. - C:\Program Files\Trend Micro\Internet Security\tmproxy.exe

And here are the results of the microworld anti-virus:

File C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
File c:\windows\system32\elitecme32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
Object "FunWeb Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "IBIS Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MyWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "FunWeb Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "FunWebProducts Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "mwsoemon Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "EliteBar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "bearsharechatnotifymsg Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "New.net Startup Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "MyWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\CoverDesigner\covered-deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Ahead\Nero BackItUp\BackItUp-Deu.nls". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Sony Shared\OpenMG\ekb\newekb020311.txt". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\Macromed\Flash\swflash.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{63CCB35F-4B6C-11D2-BA18-00A024BF101B}" refers to invalid object "C:\Program Files\Canon\ZoomBrowser EX\PhotoRecord\OpPrintCom\OpPrintCom.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6BEA1C48-1850-486C-8F58-C7354BA3165E}" refers to invalid object "C:\Program Files\Picasa\pinstall.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{92FA2C24-253C-11d2-90FB-006008A1F441}" refers to invalid object "a3dapi.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E1C1B11B-E049-47BB-A0A9-8004FF5CB831}" refers to invalid object "C:\WINDOWS\System32\MatAdown.dll". Action Taken: No Action Taken.
Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
Entry "HKCR\WMPShell.HWEventHandler.1" refers to invalid object "{9B186A8F-F520-4eeb-B553-118304AC46C5}". Action Taken: No Action Taken.
File C:\WINDOWS\NDNuninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
File C:\WINDOWS\system32\dbaccess.exe infected by "Trojan.Win32.Dialer.gp" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\elitedbz32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\osconfig.dll tagged as not-a-virus:RiskWare.Proxy.MarketScode.c. No Action Taken.
File C:\WINDOWS\system32\temperror32.dat infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\Temp\saveinstwm.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\Temp\VVSNInst.exe tagged as "not-a-virus:AdWare.Whenu.a". Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\GHUZ0LAN\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\MPDUJEXK\ads2[1].htm infected by "Trojan-Clicker.JS.Linker.f" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\MPDUJEXK\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\NBT7FLKS\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\P7BN9TCE\dbaccess[1].exe infected by "Trojan.Win32.Dialer.gp" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\P7BN9TCE\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\RZLDH91E\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\SJ5F6MRP\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\SJ5F6MRP\regular_plugin[1].exe infected by "Trojan-Downloader.Win32.IstBar.ja" Virus! Action Taken: No Action Taken.
File C:\DOCUME~1\Tommy\LOCALS~1\TEMPOR~1\Content.IE5\ZU87VHWX\jocker[1].exe infected by "Trojan-Dropper.Win32.Agent.hk" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temp\saveinstwm.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temp\VVSNInst.exe tagged as "not-a-virus:AdWare.Whenu.a". Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\GHUZ0LAN\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\MPDUJEXK\ads2[1].htm infected by "Trojan-Clicker.JS.Linker.f" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\MPDUJEXK\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\NBT7FLKS\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\P7BN9TCE\dbaccess[1].exe infected by "Trojan.Win32.Dialer.gp" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\P7BN9TCE\prompt[1].htm infected by "Trojan-Downloader.JS.IstBar.j" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\RZLDH91E\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\SJ5F6MRP\deliver46860uk[1].htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\SJ5F6MRP\regular_plugin[1].exe infected by "Trojan-Downloader.Win32.IstBar.ja" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\Local Settings\Temporary Internet Files\Content.IE5\ZU87VHWX\jocker[1].exe infected by "Trojan-Dropper.Win32.Agent.hk" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\Tommy\ysbinstall_1000489_3.exe infected by "Trojan-Downloader.Win32.IstBar.ja" Virus! Action Taken: No Action Taken.
File C:\Program Files\BearShare\Installer\BSINSTALL.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Program Files\BearShare\Installer\saveinstwm.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Program Files\Installers\BSINSTALL.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Program Files\Installers\BSINSTALL1.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Program Files\NewDotNet\newdotnet6_38.dll tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
File C:\Program Files\NewDotNet\uninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
File C:\Program Files\Screensavers\marinefree.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\Program Files\Trend Micro\Internet Security\QUARANTINE\2.tmp infected by "Trojan-Downloader.Java.OpenStream.t" Virus! Action Taken: No Action Taken.
File C:\Program Files\Trend Micro\Internet Security\QUARANTINE\3.tmp infected by "Trojan-Downloader.Win32.Small.zk" Virus! Action Taken: No Action Taken.
File C:\Program Files\Trend Micro\Internet Security\QUARANTINE\4.tmp infected by "Trojan-Dropper.Win32.Agent.hh" Virus! Action Taken: No Action Taken.
File C:\Program Files\Trend Micro\Internet Security\QUARANTINE\8.tmp infected by "Trojan-Downloader.Win32.Small.zk" Virus! Action Taken: No Action Taken.
File C:\Program Files\Trend Micro\Internet Security\QUARANTINE\F.tmp infected by "Trojan-Dropper.Win32.DNet.b" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP241\A0022212.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP293\A0024758.exe tagged as "not-a-virus:[bleep]-Dialer.Win32.Intexdial". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP304\A0025408.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP304\A0025409.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP306\A0025520.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP307\A0025542.dll tagged as not-a-virus:RiskWare.Proxy.MarketScode.c. No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP307\A0025543.dll tagged as not-a-virus:RiskWare.Proxy.MarketScode.c. No Action Taken.
File C:\System Volume Information\_restore{FFB1644D-ACF4-47EE-92E3-666C7B38D773}\RP310\A0025640.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\Downloaded Program Files\on-line.exe infected by "Trojan.Win32.Dialer.bh" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\NDNuninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\FSTQV3FV\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\K9W3SGJK\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dbaccess.exe infected by "Trojan.Win32.Dialer.gp" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\elitedbz32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\osconfig.dll tagged as not-a-virus:RiskWare.Proxy.MarketScode.c. No Action Taken.
File C:\WINDOWS\system32\temperror32.dat infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken.

At this point any help you could give me would be massively appreciated as its getting into exam time and I'd love my computer to be working!!

Cheers
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP