Can we do the following please, not all may be necessary
But if we miss a step, you could get reinfected
Can you please disable Ad-Aware's Ad-Watch and leave it disabled until we get you clean
It's a great feature, but can interfere with any fixes we try
As it protects parts of the registry
Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:
Security IGuard
Virtual Maid
Search MaidExit Add/Remove programs
*Download and then Install
Ewido Trojan ScannerWhen installing, under "Additional Options"
Uncheck "Install background guard" and "Install scan via context menu".
When you run ewido for the first time, you will get a warning "Database could not be found!". Click OK. We'll fix that later
From the main ewido screen, click on
Update in the left menu, then click the
Start update button.
After the update finishes (the status bar at the bottom will display "Update successful")
Close out Ewido for now, we'll need it later
*Download the
Killbox by Option^Explicit.
[color=\"red\"]*In the event you already have Killbox, this is a new version that I need you to download[/color].
* Save it to your desktop or a folder
Please Print this out or save these instructions to a Notepad file and save it to your Desktop or a folder
[color=\"red\"]I need you to copy all of the Killbox file paths below and paste them into Notepad.[/color]To open a Notepad file
Go to START>>RUN>>type in
notepadHit OK
Save this file
* Double-click
Killbox.exe to run it.
* Select "
Delete on Reboot".
* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C
[color=\"purple\"]Killbox file paths between dotted lines[/color]=========================================
C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\system32\hhk.dll
C:\Windows\System32\wldr.dll
C:\Windows\System32\helper.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe
C:\WINDOWS\System32\spoolsrv32.exe
C:\WINDOWS\Web\desktop.html
C:\WINDOWS\svchost.exe==========================================
* Return to Killbox, go to the
File menu, and choose "
Paste from Clipboard".
* Click the red-and-white "
Delete File" button. Click "
Yes" at the Delete on Reboot prompt. Click "
No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
[color=\"red\"]
While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.[/color]
[color=\"purple\"]
While in Safe Mode, please do the following:[/color]
Set Windows To Show Hidden Files and Folders
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Uncheck the Hide Extensions for known file types
* Click Yes to confirm.
* Click OK.
Delete the following folders, if they exist:
C:\Program Files\
Search MaidC:\Program Files\
Security IGuardC:\Program Files\
Virtual MaidC:\Windows\System32\
Log FilesDo a full scan with Ewido and save the report when it's done
Do another scan with Hijackthis and put a check next to these entries:
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\RunOnce: [Srv32 spool service] C:\WINDOWS\System32\spoolsrv32.exe
O9 - Extra button: Microsoft AntiSpyware helper - {33501EAF-7120-435A-91CF-EFF5D8CF1AF7} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {33501EAF-7120-435A-91CF-EFF5D8CF1AF7} - (no file) (HKCU)
ALL 018 entries, except for one, you choose
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)After you have ticked the above entries, close
All other open windows,
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
Restart back to Normal mode
Ensure that Norton's is up to date a run a full system scan
Go to START>>RUN>>Type in
msconfigHit OK
Do a NORMAL startup>>Apply it and close out
DON'T restart the computer yet
Instead
Run another scan with Hijackthis and post the fresh log
Also, post the report from Ewidos
Could you also
Download and UNZIP to desktop
Get2.zip so you now have Get2.bat extracted to the desktop
Doulble click on Get2.bat and a text file called Export2.txt will be produced
Copy and paste back Export2.txt also