I have severe problems posting so i'm breaking the post in mutiple posts.
I have put the whole text at http://web.orbitel.bg/igel/1.txt
I believe I've done most of the debugging and fixing myself but
My gf managed to add some spyware to her computer last saturday.
It was spysherrif - very nasty thing(blue desktop etc), coolwebsearch and some other I cannot find what. Some nasty proucess was reading all the harddrives and comsumed around 800mb of mem - i was afraid that it may be encrypting the disk and then ransome for money. There were two apparenty vb applications - smartdownloader paytime teatime.
The systems was win 2003 server with sp1 and all possible updates, no on-access anti-virus with dep turned only for windows system internals.
I managed to run ad-aware in safe mode, it removed some of the stuff, but no spysherrif. I used captive ndis emulation in linux to enable write support on the ntfs volme, deleted all temporary and cache files, prefetch, dll backup store.
There was this file mpcsrv.exe - i was not able to delete it so I just put 0s in the file with hex editor - no headers no nothing. All entries to suspicious files in the run clauses of the registry i deleted in safe mode and also via msconfig selected only minimal startup. Also there were many html files with names like wallpaper.html or secur32.html wich seemed to load a registry key with some app. All the desktop.ini files were the same - with another regkey to load. I've deleted all this files
However the explorer shell kept crashing and crashing every 10 secs, i managed to see that when this happens two new prouceses appear in the tasklist - on of them must have been dr watson because the harddrive started flooding with memory dumps.
Edited by i4ko, 22 December 2005 - 01:48 AM.