Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Major Internet problems [CLOSED]


  • This topic is locked This topic is locked

#1
Morian

Morian

    Member

  • Member
  • PipPip
  • 20 posts
Hi this is Steven

I got some problems with my PC...

I got a desktop, saying:
""'Warning, your computer might be infected with spyware or adware !!!

Strange ,homepage, popups loss of important data and unstable functioning are the sure signs that you are infected.

it also loads PSGuard, SideBar, Surf Side Kick, Weird Web and a few IE tool bars

here is my HiJackThis log

Logfile of HijackThis v1.99.1
Scan saved at 10:08:17, on 29/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\srvprc.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\Program Files\Screen Calendar\scrcal.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-au\msnappau.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jucheck.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\FlashEnc\FlashEnc.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
C:\Program Files\SSC\Ssc.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\wuauclt.exe
c:\slinstaller.exe
C:\WINDOWS\system32\3.exe
C:\WINDOWS\system32\intell32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SSK3_B5.exe
C:\DOCUME~1\STEVEN~1\LOCALS~1\Temp\i3.tmp
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\stubinstaller5975.exe
C:\WINDOWS\shop1004.exe
C:\program files\internet explorer\iexplore.exe
C:\DOCUME~1\STEVEN~1\LOCALS~1\Temp\fl1rA29.exe
C:\WINDOWS\installer_SIAC.exe
C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe
C:\Program Files\Internet Optimizer\optimize.exe
C:\Program Files\ISTsvc\istsvc.exe
C:\WINDOWS\fqfgupfl.exe
C:\Documents and Settings\Steven Galvin\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\strpfstcfg.exe" -run -SFAURUN -SFCURUN -SFAUSTARTUP -SFCUSTARTUP
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\system32\intell32.exe
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [WeirdOnTheWeb] "C:\Program Files\WeirdOnTheWeb\WeirdOnTheWeb.exe"
O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
O4 - HKLM\..\Run: [HmfneF] C:\WINDOWS\fqfgupfl.exe
O4 - HKCU\..\Run: [Spam Bully for Outlook Express] "C:\Program Files\Axaware\Spam Bully 2 for OE\oespambully.exe" install
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Screen Calendar] "C:\Program Files\Screen Calendar\scrcal.exe" -m
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\WINDOWS\stubinstaller5975.exe"
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.giga...bject/Dldrv.ocx
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c6.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestat...ab?ver=1,1,0,32
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1111554518081
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1111554475096
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06CEE1B4-51AF-465E-A270-41F01A0AE3A8}: NameServer = 61.9.192.14,61.9.192.15
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CS2\Services\Tcpip\..\{06CEE1B4-51AF-465E-A270-41F01A0AE3A8}: NameServer = 61.9.192.14,61.9.192.15
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O17 - HKLM\System\CS3\Services\Tcpip\..\{06CEE1B4-51AF-465E-A270-41F01A0AE3A8}: NameServer = 61.9.192.14,61.9.192.15
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = vic.bigpond.net.au
O20 - Winlogon Notify: avpx32 - C:\WINDOWS\SYSTEM32\avpx32.dll
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegWorks Backup Service (RWBackupSrv) - Unknown owner - C:\Program Files\RegWorks\BackupSrv.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
  • 0

Advertisements


#2
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Hi and welcome to GeeksToGo! My name is Sam and I will be helping you. :tazz:

First we need to download and prepare some tools that we will need to fix your problem.
  • Please download SmitRem.zip
    • Save the file to your desktop.
    • Right click on the file and extract it to it's own folder on the desktop.
  • Please download Ewido Security Suite
    • Install ewido security suite
    • When installing, under "Additional Options" uncheck..
      • Install background guard
      • Install scan via context menu
    • Launch ewido, there should be an icon on your desktop, double-click it.
    • You will need to update ewido to the latest definition files.
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    • Exit ewido. DO NOT scan yet.
    If you are having problems with the updater, you can use this link to manually update ewido.
    Ewido Manual Updates

  • Please download Adaware SE 1.06
    Install Adaware and check for updates, but don't run it yet.

  • Place a shortcut to Panda ActiveScan on your desktop.
=============


Now that you have the right tools we can start fixing your problem.
Please print out these instructions as the rest of this fix must be done in Safe mode and you won't be able to access the Internet.

Please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
* if you have trouble getting into Safe mode go here for more info.


=============


Once in Safe mode, follow these steps:
  • Open the smitRem folder, then double click the RunThis.bat file to start the tool.
    • Follow the prompts on screen.
    • Wait for the tool to complete and disk cleanup to finish.
    • The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
  • Open Ad-aware and do a full scan. Remove everything that it finds.

  • Run Ewido:
    • Click on scanner
    • Click Complete System Scan and the scan will begin.
    • During the scan it will prompt you to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
    • When the scan is finished, click the Save report button at the bottom of the screen.
    • Save the report to your desktop.
    • Close Ewido.
  • Next go to Control Panel click Display > Desktop > Customize Desktop > Website > Uncheck "Security Info" if present.

  • Reboot back into normal mode and click the Panda ActiveScan shortcut, then do a full system scan. Make sure the autoclean box is checked!

  • Save the scan log and post it along with a new HijackThis Log, the contents of the smitfiles.txt log and the Ewido Log by using Add Reply.
Let me know if any problems persist.
  • 0

#3
Morian

Morian

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Every time that I run smitRem in Safe Mode is get a blue creen o' death :tazz:

Not sure if I'm doing anything wrong, maybe. ;)
  • 0

#4
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
That's ok. Just skip that step for now and proceed with the rest of the fix.
  • 0

#5
Morian

Morian

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Ok I had a few problems getting these logs if they are not exactly what you need then please tell me I can run the programs again...



Incident Status Location

Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\intell32.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\2.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\srvprc.exe
Adware:adware/psguard No disinfected C:\WINDOWS\SYSTEM32\intell32.exe
Adware:adware/weirdontheweb No disinfected C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\FAVORITES\WeirdOnTheWeb.url
Spyware:spyware/surfsidekick No disinfected C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\APPLICATION DATA\Sskcwrd.dll
Adware:adware/isearch No disinfected C:\WINDOWS\deskbar.ini
Adware:adware/ncase No disinfected C:\PROGRAM FILES\180searchassistant
Adware:adware/powerscan No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\POWER SCAN
Adware:adware/topconvert No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TPUSN
Adware:adware/novo No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\NOVO
Spyware:spyware/media-motor No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\REVISIONS
Spyware:spyware/bargainbuddy No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\BARGAINBUDDY
Spyware:spyware/dyfuca No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\INTERNET OPTIMIZER
Spyware:spyware/istbar No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\ISTSVC
Adware:adware/ucmore No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\UCMORE - THE SEARCH ACCELERATOR
Adware:adware/sidefind No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{10E42047-DEB9-4535-A118-B3F6EC39B807}
Adware:adware/wupd No disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
Adware:adware/cws No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{10e42047-deb9-4535-a118-b3f6ec39b807}
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\01808300\3772.tmp
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180SAAX.cab[clientax.inf]
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180SAAX.cab[clientax.dll]
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180sainstallersilsais1.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\bb.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\Del197.tmp
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\fl1rA29.exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\optimize.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\res198.tmp
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\sidefind.exe
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\44W13SJE\ysb[1].dll
Adware:Adware/Tracking No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\advertising[1].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\bb[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\istrecover[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\sidefind[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\ys[1].exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\5076[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\istsvc[1].exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\loader52[1].exe
Virus:Trj/Dropper.KW Disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\package_MARKETING27[1].exe
Adware:Adware/PowerScan No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\power_remove[1].exe
Adware:Adware/SideFind No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\sidefind13[1].dll
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\stubinstaller5041[1].ex_
Adware:Adware/TopConvert No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\tclite[1].exe
Adware:Adware/Tracking No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\advertising[1].htm
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\istdownload[1].exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\nem220[1].dll
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\optimize[1].exe
Adware:Adware/SideFind No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\sfbho13[1].dll
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\webservice[2].htm
Adware:Adware/nCase No disinfected C:\Program Files\180searchassistant\sais.exe
Adware:Adware/nCase No disinfected C:\Program Files\180searchassistant\saishook.dll
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\adv.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\adx.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\bargains.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\Uninstall.exe
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\optimize.exe
Spyware:Spyware/ISTbar No disinfected C:\Program Files\ISTsvc\istsvc.exe
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan\powerscan.exe
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan\uninstall.exe
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind\sfbho.dll
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind\sidefind.dll
Spyware:Spyware/ISTbar No disinfected C:\Program Files\SideFind\update\sidefind.exe
Spyware:Spyware/YourSiteBar No disinfected C:\Program Files\YourSiteBar\ysb.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\ClientAX.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\clientax.inf
Adware:Adware/nCase No disinfected C:\WINDOWS\fwjez.exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\nem220.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\1.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\2.exe
Adware:Adware/TopConvert No disinfected C:\WINDOWS\system32\4.exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\5.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl0.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl1.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul1.exe
Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\intell32.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\javexulm.vxd
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\mqexdlm.srg
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\msbe.dll
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\srvprc.exe
Spyware:Spyware/XXXToolbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temp\backups\backup-20040927-103413-410
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temp\backups\backup-20040927-103413-410.inf
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temporary Internet Files\Content.IE5\WHYR05YB\zone[1]
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temporary Internet Files\Content.IE5\WHYR05YB\zone[2]
====================================================

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 07:35:19, 2/08/2005
+ Report-Checksum: 6E1D46E5

+ Scan result:

HKLM\SOFTWARE\Classes\Interface\{339D8AFF-0B42-4260-AD82-78CE605A9543} -> Spyware.SideFind : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{A36A5936-CFD9-4B41-86BD-319A1931887F} -> Spyware.SideFind : Cleaned with backup
HKLM\SOFTWARE\eXactUtil -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{99410CDE-6F16-42ce-9D49-3807F78F0287} -> Spyware.Zango : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Update\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Spyware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\sais -> Spyware.180Solutions : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar -> Spyware.ISTBar : Cleaned with backup
HKLM\SOFTWARE\YourSiteBar\Historycompare_item -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1614895754-1682526488-725345543-1003\Software\PowerScan -> Spyware.PowerScan : Cleaned with backup
[3192] C:\WINDOWS\system32\2.exe -> Trojan.Agent.eo : Cleaned with backup
[3208] C:\WINDOWS\system32\intell32.exe -> Trojan.Small.ev : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Cookies\steven galvin@ysbweb[1].txt -> Spyware.Cookie.Ysbweb : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180sainstallersilsais1.exe/clientax.dll -> Spyware.180Solutions : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\44W13SJE\X[1].exe -> Dialer.Generic : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\ys[1].exe -> TrojanDropper.Agent.ex : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\power_remove[1].exe -> TrojanDownloader.IstBar.gi : Cleaned with backup
C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\tclite[1].exe -> TrojanDownloader.Small.aqt : Cleaned with backup
C:\Program Files\Power Scan\uninstall.exe -> TrojanDownloader.IstBar.gi : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Spyware.180Solutions : Cleaned with backup
C:\WINDOWS\system32\4.exe -> TrojanDownloader.Small.aqt : Cleaned with backup
C:\WINDOWS\system32\5.exe -> TrojanDropper.Agent.ex : Cleaned with backup
C:\WINDOWS\system32\bbchk.exe -> Spyware.BargainBuddy : Cleaned with backup


::Report End

====================================================


smitRem log file
version 2.2

by noahdfear

The current date is: Tue 02/08/2005
The current time is: 0:26:57.68

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

oleext.dll


~~~ Windows directory ~~~



~~~ Drive root ~~~

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~

oleext.dll


~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Wininet.dll ~~~

wininet.dll INFECTED!! Starting replacement procedure.


~~~~ Looking for C:\WINDOWS\system32\dllcache\wininet.dll ~~~~


~~~~ C:\WINDOWS\system32\dllcache\wininet.dll Present! ~~~~


~~~~ Checking dllcache\wininet.dll for infection ~~~~


~~~~ dllcache\wininet.dll Clean! ~~~~

~~~ Replaced wininet.dll from dllcache ~~~



~~~ Upon reboot ~~~

wininet.old present!
oleadm.dll not present!
oleext.dll present!


~~~ Upon completion ~~~

wininet.old not present!
oleadm.dll not present!
oleext.dll not present!


~~~~ Rechecking C:\WINDOWS\system32\wininet.dll for infection ~~~~


~~~~ C:\WINDOWS\system32\wininet.dll Clean! :tazz: ~~~~

====================================================

Logfile of HijackThis v1.99.1
Scan saved at 07:48:17, on 2/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\srvprc.exe
C:\Program Files\Screen Calendar\scrcal.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-au\msnappau.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\FlashEnc\FlashEnc.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\SSC\Ssc.exe
C:\Program Files\Xfire\Xfire.exe
C:\Documents and Settings\Steven Galvin\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00668278-29E6-1518-8500-2A24F05407AA} - C:\Program Files\cdmweb\mhpknrxxjh.dll (file missing)
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" "+b1"
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.giga...bject/Dldrv.ocx
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c6.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestat...ab?ver=1,1,0,32
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1111554518081
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1111554475096
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O20 - Winlogon Notify: avpx32 - C:\WINDOWS\SYSTEM32\avpx32.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegWorks Backup Service (RWBackupSrv) - Unknown owner - C:\Program Files\RegWorks\BackupSrv.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe

again if they are not right then please inform me...cheers
  • 0

#6
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
You did great! :tazz:
I know it's not easy doing all this stuff on a sick computer. :)


Please download and install Cleanup 4.0, but don't run it yet.


Please download HSFix
After it is downloaded, create a new folder on your desktop called "HSFix" and extract all the files into the newly created folder.



Please make sure that you can VIEW ALL HIDDEN FILES.

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then close all other windows--you should only see HijackThis on your Desktop--and click the Fix Checked button.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00668278-29E6-1518-8500-2A24F05407AA} - C:\Program Files\cdmweb\mhpknrxxjh.dll (file missing)
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)

fix these next four lines unless you or an admistrator put these in place
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...e/bridge-c6.cab
O20 - Winlogon Notify: avpx32 - C:\WINDOWS\SYSTEM32\avpx32.dll




Please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
* if you have trouble getting into Safe mode go here for more info.


Locate the HSFix folder on your desktop, open it, and double-click "hsfix.bat"
A log will be produced which you can close out of.


Delete these files or directories (Do not be concerned if they do not exist):

C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\FAVORITES\WeirdOnTheWeb.url
C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\APPLICATION DATA\Sskcwrd.dll
C:\Program Files\180searchassistant
C:\Program Files\BullsEye Network
C:\Program Files\Internet Optimizer
C:\Program Files\ISTsvc
C:\Program Files\Power Scan
C:\Program Files\SideFind
C:\Program Files\YourSiteBar
C:\Program Files\cdmweb
C:\WINDOWS\Downloaded Program Files\ClientAX.dll
C:\WINDOWS\Downloaded Program Files\clientax.inf
C:\WINDOWS\fwjez.exe
C:\WINDOWS\deskbar.ini
C:\WINDOWS\nem220.dll
C:\WINDOWS\system32\1.exe
C:\WINDOWS\system32\2.exe
C:\WINDOWS\system32\4.exe
C:\WINDOWS\system32\5.exe
C:\WINDOWS\system32\exdl.exe
C:\WINDOWS\system32\exdl0.exe
C:\WINDOWS\system32\exdl1.exe
C:\WINDOWS\system32\exul.exe
C:\WINDOWS\system32\exul1.exe
C:\WINDOWS\system32\javexulm.vxd
C:\WINDOWS\system32\mqexdlm.srg
C:\WINDOWS\system32\msbe.dll
C:\WINDOWS\system32\srvprc.exe



Run CleanUp! and let it clean your computer of temp files. Decline when it asks you to log off.


Run a full scan with Ewido.


Reboot your computer to go back to normal mode.
Run a new Panda online virus scan.


Reboot once more and post this information for me to review.
  • HSFix log which is located at C:/hslog.txt
  • Hijackthis log
  • Ewido log
  • Log from Panda online virus scan
Again, do the best you can. Note any problems that you have and let me know in your next reply.

;)
  • 0

#7
Morian

Morian

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Here's the next lot of scans


Incident Status Location

Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\intell32.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\2.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\srvprc.exe
Adware:adware/psguard No disinfected C:\WINDOWS\SYSTEM32\intell32.exe
Adware:adware/weirdontheweb No disinfected C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\FAVORITES\WeirdOnTheWeb.url
Spyware:spyware/surfsidekick No disinfected C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\APPLICATION DATA\Sskcwrd.dll
Adware:adware/isearch No disinfected C:\WINDOWS\deskbar.ini
Adware:adware/ncase No disinfected C:\PROGRAM FILES\180searchassistant
Adware:adware/powerscan No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\POWER SCAN
Adware:adware/topconvert No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\CLASSES\TPUSN
Adware:adware/novo No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\NOVO
Spyware:spyware/media-motor No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\REVISIONS
Spyware:spyware/bargainbuddy No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\BARGAINBUDDY
Spyware:spyware/dyfuca No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\INTERNET OPTIMIZER
Spyware:spyware/istbar No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\ISTSVC
Adware:adware/ucmore No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP MANAGEMENT\ARPCACHE\UCMORE - THE SEARCH ACCELERATOR
Adware:adware/sidefind No disinfected HKEY_CURRENT_USER\SOFTWARE\MICROSOFT\INTERNET EXPLORER\EXTENSIONS\CMDMAPPING\{10E42047-DEB9-4535-A118-B3F6EC39B807}
Adware:adware/wupd No disinfected HKEY_LOCAL_MACHINE\Software\Microsoft\Code Store Database\Distribution Units\{15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6}
Adware:adware/cws No disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\extensions\CmdMapping\{10e42047-deb9-4535-a118-b3f6ec39b807}
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\01808300\3772.tmp
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180SAAX.cab[clientax.inf]
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180SAAX.cab[clientax.dll]
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\180sainstallersilsais1.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\bb.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\Del197.tmp
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\fl1rA29.exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\optimize.exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\res198.tmp
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temp\sidefind.exe
Spyware:Spyware/YourSiteBar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\44W13SJE\ysb[1].dll
Adware:Adware/Tracking No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\advertising[1].htm
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\bb[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\istrecover[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\sidefind[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\YHO1OPEX\ys[1].exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\5076[1].exe
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\istsvc[1].exe
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\loader52[1].exe
Virus:Trj/Dropper.KW Disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\package_MARKETING27[1].exe
Adware:Adware/PowerScan No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\power_remove[1].exe
Adware:Adware/SideFind No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\sidefind13[1].dll
Adware:Adware/nCase No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\stubinstaller5041[1].ex_
Adware:Adware/TopConvert No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\Z376YYN3\tclite[1].exe
Adware:Adware/Tracking No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\advertising[1].htm
Spyware:Spyware/ISTbar No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\istdownload[1].exe
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\nem220[1].dll
Spyware:Spyware/Dyfuca No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\optimize[1].exe
Adware:Adware/SideFind No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\sfbho13[1].dll
Spyware:Spyware/BargainBuddy No disinfected C:\Documents and Settings\Steven Galvin\Local Settings\Temporary Internet Files\Content.IE5\ZPF4A8XA\webservice[2].htm
Adware:Adware/nCase No disinfected C:\Program Files\180searchassistant\sais.exe
Adware:Adware/nCase No disinfected C:\Program Files\180searchassistant\saishook.dll
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\adv.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\adx.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\bin\bargains.exe
Spyware:Spyware/BargainBuddy No disinfected C:\Program Files\BullsEye Network\Uninstall.exe
Spyware:Spyware/Dyfuca No disinfected C:\Program Files\Internet Optimizer\optimize.exe
Spyware:Spyware/ISTbar No disinfected C:\Program Files\ISTsvc\istsvc.exe
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan\powerscan.exe
Adware:Adware/PowerScan No disinfected C:\Program Files\Power Scan\uninstall.exe
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind\sfbho.dll
Adware:Adware/SideFind No disinfected C:\Program Files\SideFind\sidefind.dll
Spyware:Spyware/ISTbar No disinfected C:\Program Files\SideFind\update\sidefind.exe
Spyware:Spyware/YourSiteBar No disinfected C:\Program Files\YourSiteBar\ysb.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\ClientAX.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\clientax.inf
Adware:Adware/nCase No disinfected C:\WINDOWS\fwjez.exe
Spyware:Spyware/Dyfuca No disinfected C:\WINDOWS\nem220.dll
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\1.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\2.exe
Adware:Adware/TopConvert No disinfected C:\WINDOWS\system32\4.exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\system32\5.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl0.exe
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\exdl1.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\exul1.exe
Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\intell32.exe
Adware:Adware/ExactSearch No disinfected C:\WINDOWS\system32\javexulm.vxd
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\mqexdlm.srg
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\msbe.dll
Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\system32\srvprc.exe
Spyware:Spyware/XXXToolbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temp\backups\backup-20040927-103413-410
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temp\backups\backup-20040927-103413-410.inf
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temporary Internet Files\Content.IE5\WHYR05YB\zone[1]
Spyware:Spyware/ISTbar No disinfected F:\C Drive\Documents and Settings\Steven Galvin.STEVEN\Local Settings\Temporary Internet Files\Content.IE5\WHYR05YB\zone[2]
===================================================

Logfile of HijackThis v1.99.1
Scan saved at 07:52:23, on 3/08/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Microsoft.NET\Framework\v2.0.40607\aspnet_admin.exe
C:\WINDOWS\system32\ZoneLabs\isafe.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Screen Calendar\scrcal.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\MSN Apps\Updater\01.03.0000.1005\en-au\msnappau.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Startup Faster 2004\sfAgent.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
c:\FlashEnc\FlashEnc.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\SSC\Ssc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Steven Galvin\Desktop\HijackThis.exe

O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O3 - Toolbar: ninemsn - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-au\msntb.dll
O4 - HKLM\..\Run: [StartupFaster] "C:\Program Files\Startup Faster 2004\StrpFstCfg.exe" -run SFAURUN SFCURUN SFAUSTARTUP SFCUSTARTUP
O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0D6709DD-4ED8-40CA-B459-2757AEEF7BEE} (Dldrv2 Control) - http://download.giga...bject/Dldrv.ocx
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {2359626E-7524-4F87-B04E-22CD38A0C88C} (ICSScannerLight Class) - http://download.zone...ee/cm/ICSCM.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_1_0_0_44.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.imagestat...ab?ver=1,1,0,32
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1111554518081
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1111554475096
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegWorks Backup Service (RWBackupSrv) - Unknown owner - C:\Program Files\RegWorks\BackupSrv.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

====================================================

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 06:58:09, 3/08/2005
+ Report-Checksum: 325694B9

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{357A87ED-3E5D-437d-B334-DEB7EB4982A3} -> Trojan.Agent.eo : Cleaned with backup
C:\RECYCLER\S-1-5-21-1614895754-1682526488-725345543-1003\Dc27.exe -> TrojanDropper.Agent.ex : Cleaned with backup
C:\RECYCLER\S-1-5-21-1614895754-1682526488-725345543-1003\Dc28.exe -> TrojanDownloader.Small.aqt : Cleaned with backup
C:\WINDOWS\system32\ysbinstall_1002924_1.exe -> TrojanDownloader.IstBar.gv : Cleaned with backup


::Report End

===================================================


Horseserver Removal Tool v1.05
by Atri
-
-
1. Registry Fix Started
-
Registry fix complete
-
2. Deleted Services
-
-
3. Finding files Located on system
-
-
4. Deleting files that were found.
-
-
5. Checking for and Removing Winupdate
-
-
-
================================================

Sorry for the blank HSLog I ran it twice accidentaly but it did delete the services that were causing problems it also deleted 1 file.

Not a good thing for a Geek U in Training to forget :tazz:

Steven
  • 0

#8
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Your hijackthis log looks clean to me! :tazz:

The only concern I have is the log from Panda. It appears to be the same log you posted in your previous post. Can you double check on that for me?

How is everything running for you? Any problems?
  • 0

#9
Morian

Morian

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Oops sorry I thought I saved the log to the desktop

Here's the newsest Panda log


Incident Status Location

Spyware:spyware/bargainbuddy No disinfected C:\WINDOWS\SYSTEM32\exclean.exe
Adware:adware/psguard No disinfected C:\WINDOWS\SYSTEM32\intell32.exe
Spyware:spyware/surfsidekick No disinfected C:\DOCUMENTS AND SETTINGS\STEVEN GALVIN\APPLICATION DATA\Sskknwrd.dll
Adware:adware/isearch No disinfected Windows Registry
Hacktool:Hacktool/Processor No disinfected C:\Documents and Settings\Steven Galvin\Desktop\HSFix\Process.exe
Hacktool:Hacktool/Processor No disinfected C:\Documents and Settings\Steven Galvin\Desktop\HSFix.zip[Process.exe]
Adware:Adware/nCase No disinfected C:\RECYCLER\S-1-5-21-1614895754-1682526488-725345543-1003\Dc26.exe
Spyware:Spyware/BargainBuddy No disinfected C:\RECYCLER\S-1-5-21-1614895754-1682526488-725345543-1003\Dc29.exe
Adware:Adware/PsGuard No disinfected C:\WINDOWS\system32\intell32.exe

I also found this file I should get rid of it yes?
C:\Documents and Settings\Steven Galvin\Application Data\Sskuknwrd.dll

Edited by Morian, 02 August 2005 - 09:53 PM.

  • 0

#10
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Delete these files:

C:\Documents and Settings\Steven Galvin\Application Data\Sskuknwrd.dll
C:\WINDOWS\system32\intell32.exe
C:\WINDOWS\SYSTEM32\exclean.exe



How is everything running on your end?
  • 0

#11
Buckeye_Sam

Buckeye_Sam

    Malware Expert

  • Member
  • PipPipPipPipPipPipPipPip
  • 10,019 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP