Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

SearchToolbar


  • Please log in to reply

#31
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
Adware Away found 0 in all of them.

Do you still need the Panda scan since nothing was changed?
  • 0

Advertisements


#32
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
can you tell me how many drives you have , and what OS is in each
  • 0

#33
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
2 Physical Harddrives

G = C:/ 12 gig standalone drive

D, E, F, 80 gig Harddrive Partitioned

WinXp SP1 on all drives.
  • 0

#34
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
this is going to be difficult to remove, just follow these steps 1 at a time.



STEP 1


Copy the bold text below to NOTEPAD.

call it fix.REG

save it to your desktop.

on your desktop double click on fix.REG and allow it to merge with the registry when it asks.



REGEDIT4

[-HKEY_CURRENT_USER\Software\SQ]
[-HKEY_CLASSES_ROOT\CLSID\{2662BDD7-05D6-408F-B241-FF98FACE6054}]
[-HKEY_CLASSES_ROOT\CLSID\{57E69D5A-6539-4d7d-9637-775DE8A385B4}]
[-HKEY_CLASSES_ROOT\CLSID\{6E6DD93E-1FC3-4F43-8AFB-1B7B90C9D3EB}]
[-HKEY_CLASSES_ROOT\CLSID\{3C5BA506-6C30-4738-9CED-797ACADEA8DC}]
[-HKEY_CLASSES_ROOT\Interface\{1A8B567B-BD3F-44A1-8B94-F50D37A1914E}]
[-HKEY_CLASSES_ROOT\Interface\{B8CFDC9E-E634-40E3-A51E-C097F23D53B9}]
[-HKEY_CLASSES_ROOT\Interface\{D686DB39-659A-491A-A35C-60B99495C16E}]
[-HKEY_CLASSES_ROOT\Interface\{3A021D2F-5F75-47F5-9BAB-A137E1FB015F}]
[-HKEY_CLASSES_ROOT\Interface\{32E715F3-6481-4118-A689-504312933CE6}]
[-HKEY_CLASSES_ROOT\TypeLib\{118AF62F-21B1-4492-8111-C1A03C5E09CB}]
[-HKEY_CLASSES_ROOT\TypeLib\{4D0AC936-BDE8-4EA2-B4FB-9F89E5B4C186}]
[-HKEY_CLASSES_ROOT\TypeLib\{805AF2C8-98C7-4F3C-A7C9-25EBF27567F3}]
[-HKEY_CLASSES_ROOT\TypeLib\{909E0059-F545-42DE-9D2C-CC4A3E336EC3}]
[-HKEY_CLASSES_ROOT\TypeLib\{C6C2871F-7467-4A35-90FA-9E9894BC1916}]
[-HKEY_CLASSES_ROOT\TypeLib\{43732063-1BDA-45A0-BBEE-13E014CB4041}]
[-HKEY_CLASSES_ROOT\SQToolbar.Band]
[-HKEY_CLASSES_ROOT\SQToolbar.Band.1]
[-HKEY_CLASSES_ROOT\XTSearch.XTSearchHook]
[-HKEY_CLASSES_ROOT\XTSearch.XTSearchHook.1]
[-HKEY_CLASSES_ROOT\XTUpdate.XT]
[-HKEY_CLASSES_ROOT\XTUpdate.XT.1]
[-HKEY_CLASSES_ROOT\XupiterToolbar.Band]
[-HKEY_CLASSES_ROOT\XupiterToolbar.Band.1]
[-HKEY_CLASSES_ROOT\XTUpdate.XT]
[-HKEY_CLASSES_ROOT\XTUpdate.XT.1]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units
\{3C5BA506-6C30-4738-9CED-797ACADEA8DC}]
[-HKEY_CLASSES_ROOT\Classes\SQLoader.Loader]
[-HKEY_CLASSES_ROOT\Classes\SQLoader.Loader.1]
[-HKEY_CURRENT_USER\Software\Xupiter]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Sqwire]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2662BDD7-05D6-408F-B241-FF98FACE6054}]




STEP 2


Download Killbox from here.

Double-click killbox.exe on your desktop.
Select the option "Delete on reboot".
Now highlight and 'copy' the entire list of filepaths below:



G:\WINDOWS\rdt.ini
G:\Program Files\Common Files\orku
G:\WINDOWS\system32\c.bat
C:\Program Files\Sqwire
C:\Program Files\Xupiter
C:\Program Files\Common Files\SQ


Open 'file' in the killbox menu at the top and choose 'Paste from clipboard'

Now you will see, this is pasted in the "Full Path of File to Delete"-field.
There's a little arrow (dropdown-arrow) next to that field.
If you expand it, these lines should be there together!

Then press the red button with a white X in it.
Killbox will tell you that all listed files will be deleted on next reboot.
Click YES


When it asks if you would like to Reboot now, click YES
If you get a "PendingFileRenameOperations Registry Data has been Removed by External Process!" message then just restart manually.


STEP 3


Go to C:\Documents and Settings\<Current User>\Favorites :-

and look for and delete any of these folders you find :-

Business
Computers
Cool Stuff
Entertainment
Gaming
Lifestyle
Shopping
Finance
Free Stuff
Gambling
Inernet



STEP 4



Rerun HJT,and put a checkmark beside these :-

O17 - HKLM\System\CCS\Services\Tcpip\..\{B9C39F86-0C4E-4D3E-9592-17EB9576A4F3}: NameServer = 195.95.218.1,85.255.112.7
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC049923-DCC2-4D99-8AE8-9E637BBAD3C0}: NameServer = 195.95.218.1,85.255.112.7

now close all windows and browsers and click FIX CHECKED


STEP 5


now empty your recycle bin.


STEP 6


This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.



STEP 7


Download and install Ad-aware SE from HERE
Once installed, run the program and in the bottom right hand corner click 'Check For Updates'. Update Ad-aware following the prompts and then configure and scan as per the instructions below:

1.Close ALL windows except Ad-Aware SE.

2. Click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window.

3. In the ‘GENERAL’ window make sure the following are selected in green:

*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)

-Under Definitions:
*Prompt to udate outdated definitions - set the number of days


4. Click on the ‘SCANNING’ button on the left and select in green :

-Under Driver, Folders & Files:
*Scan Within Archives

-Under Select drives & folders to scan:
*choose all hard drives

-Under Memory & Registry: (all green)
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file

5. Click on the ‘ADVANCED’ button on the left and select in green:

-Under Shell Integration:
*Move deleted files to recycle bin

-Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information

-Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT

6. Click the ‘TWEAK’ button and select in green:

-Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only

-Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot

-Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check and make Green: Include Module list in logfile

7. Click on ‘PROCEED’ to save the settings.

8. Click ‘Start

*Choose: 'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.

9. Click ‘Next’ and Ad-Aware SE will scan your hard drive with the options you have selected and clean automatically.

10. If Ad-Aware SE finds bad entries in the registry or bad files, you will receive a list of what it found in the window. Right click on any of the bad entries and click on 'select all'.

11. Click ‘NEXT

12. Close Ad-Aware SE.


then REBOOT and post a fresh HJT log and a fresh panda active scan log.
  • 0

#35
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
I am about to do the adaware step just letting you know about 2 problems so far

1 - I don't think killbox allowed me to paste all those lines in but I am not sure.
2 - AAWTMP could not be deleted from the %temp%
  • 0

#36
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
when you downloaded ADAWARE SE you must have clicked on "run" instead of "save"

when you click on "run" it puts your d/load in a temporary file. when downloading something you wish to keep.you should click on "save " and direct it to the directory where you want to store it, that way it doesn't get deleted when you clean out temp files.

just leave that AAWTMP there for now.
  • 0

#37
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
No, I am fairly sure I saved it, I never run anything from a website cept online scanners.

Although I have switched to Firefox so that might handle downloads differently than what I am used too.

Do I need to run killbox for each line seperatly?

also my dsl seems to have shut down sometime last night in the middle of the ad-aware scan, not sure of the cause yet haven't had much chance to play with it.
posting this from work.
  • 0

#38
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
Logfile of HijackThis v1.99.1
Scan saved at 9:11:36 p.m., on 4/08/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\csrss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
G:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
G:\Program Files\ewido\security suite\ewidoctrl.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\WINDOWS\System32\wdfmgr.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\SOUNDMAN.EXE
G:\WINDOWS\System32\RUNDLL32.EXE
G:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
G:\Program Files\Mozilla Firefox\firefox.exe
E:\Pauls Documents\spywareremovaltools\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.autopassion.co.nz/index.php
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - G:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] G:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] G:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE G:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [THGuard] "G:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [AVG7_CC] G:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - Global Startup: Adobe Reader Speed Launch.lnk = G:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = G:\Program Files\Office2000\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://g:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://g:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://g:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://g:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://g:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: RaptisoftGameLoader - http://www.miniclip....tgameloader.cab
O16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) - http://zone.msn.com/...bGameLoader.cab
O16 - DPF: {4B9F2C37-C0CF-42BC-BB2D-DCFA8B25CABF} (PopCapLoaderCtrl Class) - http://zone.msn.com/...pcaploader1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1122556946093
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://zone.msn.com/...me/ZAxRcMgr.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/...ro.cab34246.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/...outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/.../default/gf.cab
O16 - DPF: {DAF5D9A2-D982-4671-83E4-0398706A5F6A} (SCEWebLauncherCtl Object) - http://zone.msn.com/...WebLauncher.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/...aploader_v5.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/z...s/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B9C39F86-0C4E-4D3E-9592-17EB9576A4F3}: NameServer = 202.27.158.40,202.27.156.72
O17 - HKLM\System\CCS\Services\Tcpip\..\{BC049923-DCC2-4D99-8AE8-9E637BBAD3C0}: NameServer = 202.27.158.40,202.27.156.72
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - G:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - G:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - G:\WINDOWS\System32\nvsvc32.exe



Incident Status Location

Possible Virus. No disinfected D:\games\blizzard\shadowmaster\shadowmaster.exe
Hacktool:Hacktool/Processor No disinfected E:\Pauls Documents\spywareremovaltools\l2mfix.exe[Process.exe]
Hacktool:Hacktool/Processor No disinfected E:\Pauls Documents\Incomplete\l2mfix.exe[Process.exe]
Adware:Adware/Sqwire No disinfected G:\!Submit\orkud\orkuc.dll
Hacktool:Hacktool/Processor No disinfected G:\Documents and Settings\Paul\Desktop\l2mfix\Process.exe
Possible Virus. No disinfected G:\Documents and Settings\Paul\Local Settings\Temp\ASHeuristic\shadowmaster.exe.vir
Adware:Adware/Sqwire No disinfected G:\Program Files\Common Files\orku\orkud\orkuc.dll
Possible Virus. No disinfected G:\Program Files\TrojanHunter 4.2\Tools\Process Viewer\ProcessViewer.exe
  • 0

#39
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
Double-click killbox.exe on your desktop.
Select the option "Delete on reboot".
Now highlight and 'copy' the entire list of filepaths below:- (all together)


G:\Program Files\Common Files\orku
G:\WINDOWS\rdt.ini
G:\WINDOWS\system32\c.bat
C:\Program Files\Sqwire
C:\Program Files\Xupiter
C:\Program Files\Common Files\SQ


then go to G:\!Submit <----delete the submit folder. you may have to delete this in safe mode.


This process will clean out your Temp files and your Temporary Internet Files. Please do both steps:

Step 1:Delete Temp Files
To clean out your temp files, click on Start and then run, and type %temp% and press the ok button.

This should open up the temp directory that your machine uses. Please delete all files that are found there. If you get an error when deleting a file, skip that file and delete all the others. If you had trouble deleting a file, reboot into Safe Mode and follow this step again. You should now be able to delete all the files.

Step 2: Delete Temporary Internet Files
Now I want you to open up Internet Explorer, and click on the Tools menu and then Internet Options. At the General tab, which should be the first tab you are currently on, click on the Delete Files button and put a checkmark in Delete offline content. Then press the OK button. This may take quite a while, so do not be alarmed with how long it takes. When it is done, your Temporary Internet Files will now be deleted.


your HJT log looks clean, it is only the panda scan that is picking up remnants of the sqwire infection. hopefully this will sort it :tazz:

then just post another panda scan log.
  • 0

#40
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
AAWTMP could not be deleted in normal or safe mode
if you post the command string I will delete from command prompt either in a dos box or from F8.

Running Panda right now will post results after work.
  • 0

Advertisements


#41
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
AAWTMP is a temporary file that ADAWARE creates, so just leave it.
  • 0

#42
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
Incident Status Location

Possible Virus. No disinfected D:\games\blizzard\shadowmaster\shadowmaster.exe
Hacktool:Hacktool/Processor No disinfected E:\Pauls Documents\spywareremovaltools\l2mfix.exe[Process.exe]
Hacktool:Hacktool/Processor No disinfected E:\Pauls Documents\Incomplete\l2mfix.exe[Process.exe]
Hacktool:Hacktool/Processor No disinfected G:\Documents and Settings\Paul\Desktop\l2mfix\Process.exe
Possible Virus. No disinfected G:\Documents and Settings\Paul\Local Settings\Temp\ASHeuristic\shadowmaster.exe.vir
Adware:Adware/Sqwire No disinfected G:\Program Files\Common Files\orku\orkud\orkuc.dll
Possible Virus. No disinfected G:\Program Files\TrojanHunter 4.2\Tools\Process Viewer\ProcessViewer.exe
Adware:Adware/Sqwire No disinfected G:\RECYCLER\S-1-5-21-861567501-1957994488-725345543-1003\Dg28\orkud\orkuc.dll
Possible Virus. No disinfected G:\RECYCLER\S-1-5-21-861567501-1957994488-725345543-1003\Dg30\ProcessViewer.exe.vir
Possible Virus. No disinfected G:\RECYCLER\S-1-5-21-861567501-1957994488-725345543-1003\Dg30\shadowmaster.exe.vir
Possible Virus. No disinfected G:\RECYCLER\S-1-5-21-861567501-1957994488-725345543-1003\Dg30\shadowmaster.exe.vir.vir
  • 0

#43
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
try removing this one again with KILLBOX

G:\Program Files\Common Files\orku

and empty your recycle bin.

reboot the computer

post another panda scan.
  • 0

#44
DeSade

DeSade

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 377 posts
These panda scans take a minimum of 2 hours a piece, is there something a little faster?
  • 0

#45
bricat

bricat

    Visiting Staff

  • Visiting Consultant
  • 645 posts
try this one :-

http://uk.trendmicro...call_launch.php
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP