Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Aurora...Help. [CLOSED]


  • This topic is locked This topic is locked

#1
Moochie

Moochie

    New Member

  • Member
  • Pip
  • 2 posts
Just found this site. I am not a computer geek, although I have great respect for those who are. I need to get rid of the annoying Aurora pop ups. Am I supposed to start at the top where it says:

Do you suspect a malware (Spyware, Virus, Trojan) infection? Please start here

I did the clean up part. But looking at the rest is quite overwhelming.

Any advice?


Thanks.
Moochie
  • 0

Advertisements


#2
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Hi Moochie and welcome to GeeksToGo!


If you are having malware issues, please got to the following site and follow all the instructions carefully.


You Must Read This Before Posting A Hijackthis Log

Then please post a fresh Hijack log, in this thread, so I can help you with your Malware Problems.


Thanks,

:tazz:

Excal
  • 0

#3
Moochie

Moochie

    New Member

  • Topic Starter
  • Member
  • Pip
  • 2 posts
I think I did all those things requested. Still completely confused. Thanks for any help!

Logfile of HijackThis v1.99.1
Scan saved at 8:13:27 AM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\System32\alg.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\hkcmd.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\igfxtray.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\COMMON~1\AOL\110080~1\EE\AOLHOS~1.EXE
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\PROGRA~1\COMMON~1\AOL\110080~1\EE\AOLServiceHost.exe
C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
C:\Program Files\Desktop Alert\desktopalert_1192964.exe
C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\nqhpozgaz.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\6T4D379U\HijackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-qus9.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = C:\Program Files\AOL Toolbar\welcome.html
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5,1,1,0.dll
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "c:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Disk Monitor] C:\Program Files\IC\Card Reader Driver v1.9e2\Disk_Monitor.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [QuickFinder Scheduler] "c:\Program Files\WordPerfect Office 11\Programs\QFSCHD110.EXE"
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1100802511\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [unvqsdq] c:\windows\system32\riyftvf.exe r
O4 - HKLM\..\RunOnce: [AAW] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AOLCC] "C:\PROGRA~1\AOLCOM~1\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Sierra Imaging\Image Expert\IXApplet.exe
O4 - Startup: Compaq Organize.lnk = ?
O4 - Startup: Desktop Alert.lnk = C:\Program Files\Desktop Alert\desktopalert_1192964.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe
O4 - Global Startup: Compaq Connections.lnk = C:\Program Files\Compaq Connections\1940576\Program\BackWeb-1940576.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: PowerReg Scheduler.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) - https://secure.stamp...89/sdcregie.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish....fishActivia.cab
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com...kup/qdiagcc.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg...l_v1-0-3-17.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgall..._1/axofupld.cab
O16 - DPF: {72C9EA8F-8965-40C2-ABAD-D460A5815F86} (hostCntrlIE Class) - http://host.oddcast....ostClientIE.cab
O16 - DPF: {90051A81-3018-4826-8B38-DD60B6B53F9C} (Snapfish File Upload ActiveX Control) - http://www.snapfish....pfishUpload.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://echat.us.del...t/TLIEFlash.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai....23/cpbrkpie.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-cent...bin/actxcab.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2234B608-834B-4BA6-9C7C-9143A0105D8E}: NameServer = 205.188.146.145
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: OPXPGina - C:\Program Files\Softex\OmniPass\opxpgina.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\Program Files\Common Files\AOL\AOL Spyware Protection\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Unknown owner - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 8:01:20 AM, 7/12/2005
+ Report-Checksum: 99154767

+ Scan result:

HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Bargain Buddy -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1910449697-3724596896-3945583169-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\4PM74PU7\MediaAccK[1].exe -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Media Access\__delete_on_reboot__MediaAccess.exe -> Spyware.WinAD : Cleaned with backup
C:\Program Files\Media Access\__delete_on_reboot__MediaAccK.exe -> Spyware.WinAD : Cleaned with backup
C:\WINDOWS\cpbrkpie.ocx -> Spyware.Coupon : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\pxckdlauninstall.exe -> Spyware.NoName : Cleaned with backup
C:\WINDOWS\snbho.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\system32\aezqpjw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ahsaiz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ajjtwje.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ajyidem.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ampidc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\aujdmhx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\avdfjya.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\avmure.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ayauzo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\azzpwh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\bakrmn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\bmawnh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\bwrosa.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cakbli.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cdbofm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cgikdzt.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\chdpse.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cioqhxm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cjmkxwo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cndvlp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cnovwe.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cshlrug.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cuarclo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cuyuuii.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\cyualyr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dfhhykq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\didgit.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\djaqakd.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\djmwsnc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dmdbofu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dmhznqi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dpdequ.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dtiaid.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dtysqia.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dvijmf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dvqusa.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dvwwfxc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\dzuura.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\eaoiqf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ebxbxr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\efcwocr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\efsrsmu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ehkadsn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\evbbjww.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\evdycj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\excxyxs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fbnhfc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\feacde.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ffrghk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fgetia.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fhxonmo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\flgxoqg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fmcjgqv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fmqgik.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fpibquv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fqmpqoz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\frfymeu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ftqlxmn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fugaojs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fwzrue.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\fzjizuz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gbjlza.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gcbmgw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gcuofi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\geaczu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gguuco.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\glklgm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gotlsm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gxtzyge.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gxujwvg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gyefuw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\gzzdnjw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\heqahqo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\humhjaa.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\huzovjz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\hvjpsj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\iabdtj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\iaijxrf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\iatlne.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ieaepxv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\iejhxl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\iekuyi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ingwswg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ipvgwsv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ipytts.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\irissl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\isnjekn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\itzrli.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ivgzoq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jbbnspz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jbhymzt.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jdxilo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jemlsd.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jgdgra.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jgmmlp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jlihnjo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jqcwtax.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\jtfbdc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kecgck.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kehbnk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\keursq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kfentje.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kflmckj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kkmohkh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kkwpdgw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\klzasx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kmtqkq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kmxvgnu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kovdmik.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kpfmbcf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kquvno.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\krckrzb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\kthulj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lbbxqte.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lbzlgeb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lcbqhz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lcukul.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lfvaord.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lgfbipt.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\liqnhw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lkkdbck.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lmdowhk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lmukqs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\loufzp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\louyais.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\lpnfkul.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\luycly.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mgdvxs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mhnftc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\milxno.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mniakkz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mnpfrpc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mssqsf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mtydrzn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mwdjqu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mxooroi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\mxtfdc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\myomha.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ngsaik.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\njhbvyb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nklomu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nrplce.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nrwpxcn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nuwclg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nvfnib.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nvtoxi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\nzvpxx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\oanffm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\odaifko.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ofitpb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ofxifet.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ogrzmdw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\oieorn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\opigwze.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\osjcogg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ovcpqx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ozxpmpv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\pbzlbve.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\pevfwiy.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ptmwpuk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\pztnoko.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qandxb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qbfkoj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qeuvvb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qewmjqz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qhnxoh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qhrykma.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qlvzzxi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qnkucf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qnlrcne.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qqnaqot.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qskosv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\qwvrhel.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ranidsj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rbfmerl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rdrznuc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rijvzc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\riyftvf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rlvjdez.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rntbtw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rqdmoss.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rsigyfk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rslkiz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rsqjbzp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\rzfrgog.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\sawcpv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\schexk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\sdxnoq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\sjaexhi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\slhypwu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\slvrrzv.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\smqmgj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\smrndi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\srxgrxp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ssoghl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\sysurej.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\thrkjo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tjfgjo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tmxszy.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tqjkiyh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tsrsenl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ttleoh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\tuqzfmo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\twqfgg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ubikop.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ufdiywz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uorgpsk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\upmqvha.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\urbvcu.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uuvfkn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uxpekqm.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uypkbr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uzaqzsd.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uzpxjuc.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\uzwlabp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\vqgpiw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\vubpsp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\vuiops.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\vykevp.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\waoorjj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\whaeii.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\wrrlrq.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\wsyrus.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\wszutdo.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\wusgic.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xaegfzf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xbfdni.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xenrfqe.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xjunyi.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xlmeev.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xmmdmwn.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xonloan.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xpepaer.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xpmcfmj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xrkavb.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xtqtzma.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xwifpwj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xyllrl.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\xzufrg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\yfmpbby.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ygqfgx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\yhebxgw.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\yjblsx.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\ytzybjs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\yukbzka.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zcxmcrh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zgcwhd.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\znbgcz.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\znslis.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zntuko.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zoknnqf.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zortbh.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zstqskg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zuuzzgs.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\system32\zxmnxt.exe -> Adware.BetterInternet : Cleaned with backup
  • 0

#4
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Hi Moochie and welcome to GeeksToGo!

I can see that you have some malware issues. This maybe a few step process in removing it. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.


DOWNLOAD PROGRAMS


Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates Do NOT run a scan yet. (if you already have, please just update)

Please download Nailfix from Here
click nailfix.exe and choose install, a new folder will be created on your desktop named nailfix
please do NOT run it yet.

Download and install CleanUp! Here*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.
We will use this program later.


THE FIX


Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

1. Click this link to be sure you can view hidden files.

2. Ensure you are NOT connected to the internet.

3. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

4. Go into Hijack This->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for each one (If they still exist)

C:\WINDOWS\Nail.exe
c:\windows\system32\riyftvf.exe


5. Once in Safe Mode, please double-click on
Nailfix.cmd Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

6. Now open and run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan when it ask if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop
Close Ewido

7. Close all browsers, windows and unneeded programs.

8. Open HiJack and do a scan.

9. Put a Check next to the following items:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [unvqsdq] c:\windows\system32\riyftvf.exe r


10. click the Fix Checked box

11. Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Media Access

12. Please remove the following folders using Windows Explorer (if present):

C:\Program Files\Media Access
c:\installer


13. Please remove just the files from the following paths using Windows Explorer (if present):

c:\windows\system32\riyftvf.exe
C:\WINDOWS\Nail.exe


14. Run the program CleanUp!

15. Reboot into normal mode and please run this online virus scan: ActiveScan - Save the results from the scan!

16. Please post an Active scan log , Ewido Scan log and a fresh HiJackThis log. Let me know how your computer is running.

Edited by Excal, 12 July 2005 - 12:08 PM.

  • 0

#5
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP