i realise that someone has already post up a request to remove oneclicksearches spyware.
http://www.geekstogo...VED-t41883.html
However my log file is alot different from him (his name is Wazoo). i tried the method posted and while scanning with HJT i can only check this:
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINNT\system32\hpA011.tmp
The above is the only thing similar. I proceed to do the rest as posted.
i have use Ewido Security Suite to scan and remove further spyware and adware.
The following is my report.
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:09:35 PM, 7/18/2005
+ Report-Checksum: 37185CA0
+ Scan result:
C:\WINDOWS\system32\config\systemprofile\Cookies\administrator@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\administrator@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\marcus.lok.2004\Local Settings\Temporary Internet Files\Content.IE5\3D5W11C3\input[1].php -> Not-A-Virus.Exploit.HTML.DragDrop : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\251C3E49-CABD-4BD2-B1B6-C8CB26\F88F182C-3067-4A1B-BBFD-B10ADD -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015667.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015668.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015669.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015671.EXE -> Trojan.Agent.ay : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015672.dll -> Spyware.BiSpy : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015673.dll -> Spyware.BiSpy : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015680.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015681.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015682.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015699.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015700.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015701.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015711.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015713.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP99\A0015714.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP101\A0015759.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP101\A0015760.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP101\A0015761.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015811.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015812.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015813.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015815.dll -> Trojan.Puper.m : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015835.dll -> Trojan.Puper.m : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015844.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015845.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015846.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015870.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015871.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015872.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015883.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015884.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015885.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015893.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015894.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015895.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015907.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015908.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP102\A0015909.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015960.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015961.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015962.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015978.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015979.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0015980.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016002.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016003.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016004.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016026.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016027.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016028.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016053.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016054.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016055.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016070.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016071.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0016072.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017116.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017117.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017118.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017124.exe -> Trojan.Puper.ab : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017126.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017127.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017128.exe -> Trojan.Puper.aa : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017129.dll -> Trojan.Puper.t : Cleaned with backup
C:\System Volume Information\_restore{6C7570DF-347B-468C-827D-CC7BA11C38CA}\RP103\A0017131.exe -> Trojan.Puper.w : Cleaned with backup
::Report End
Next i use Panda ActiveScan to do a scan and there appears to be still some more spyware and adware.
Incident Status Location
Adware:adware/transponder No disinfected C:\WINDOWS\LASTGOOD\INF\speer.inf
Spyware:spyware/betterinet No disinfected C:\WINDOWS\Buddy.exe
Adware:adware/savenow No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MAGNET
Adware:adware/exactsearch No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ACTIVEX COMPATIBILITY\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}
Adware:adware/popuper No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
Adware:adware/brilliantdigitalNo disinfected HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\sprnopol.inf
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\adrmsper.inf
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\speer.inf
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\Buddy.exe
Virus:HackTool/Gendel.A No disinfected C:\gendel32.exe
They coulIncident Status Location
Adware:adware/transponder No disinfected C:\WINDOWS\LASTGOOD\INF\speer.inf
Spyware:spyware/betterinet No disinfected C:\WINDOWS\Buddy.exe
Adware:adware/savenow No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\MAGNET
Adware:adware/exactsearch No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\INTERNET EXPLORER\ACTIVEX COMPATIBILITY\{53F066F0-A4C0-4F46-83EB-2DFD03F938CF}
Adware:adware/popuper No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
Adware:adware/brilliantdigitalNo disinfected HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\sprnopol.inf
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\adrmsper.inf
Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\speer.inf
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\Buddy.exe
Virus:HackTool/Gendel.A No disinfected C:\gendel32.exe
They could not be remove. Can someone help me?