• Announcements

    • Budfred

      IE 11 copy/paste problem

      It has come to our attention that people using Internet Explorer 11 (IE 11) are having trouble with copy/paste to the forum. If you encounter this problem, using a different browser like Firefox or Chrome seems to get around the problem. We do not know what the problem is, but it seems to be specific to IE 11 and we are hopeful that Microsoft will eventually fix it.
Sign in to follow this  
Followers 0
B-aye-Gee

Please comment on HJT log

7 posts in this topic

Please review the following HJT log. I have followed your instructions for using Adaware and Spybot successfully.

Thanks

 

Logfile of HijackThis v1.97.7

Scan saved at 7:37:45 PM, on 6/23/2004

Platform: Windows 2000 SP3 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe

C:\WINNT\System32\svchost.exe

C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe

C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe

C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe

C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe

C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe

C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\System32\mspmspsv.exe

C:\WINNT\system32\svchost.exe

C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

C:\WINNT\Explorer.EXE

C:\WINNT\System32\tp4mon.exe

C:\WINNT\LTSMMSG.exe

C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe

C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe

C:\PROGRA~1\ACDSYS~1\ACDSEE\CAMDET~1.EXE

C:\PROGRA~1\mcafee.com\agent\mcagent.exe

C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe

C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe

C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe

C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

C:\installer\id53.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Backup\sdbackup.exe

C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe

C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\System32\XlnkK60.exe

C:\WINNT\System32\Qmy7M.exe

C:\WINNT\System32\wuauclt.exe

C:\PROGRA~1\WINZIP\winzip32.exe

C:\Documents and Settings\ekalb.ED\Local Settings\Temp\HijackThis.exe

 

R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe

O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot

O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\ACDSEE\CAMDET~1.EXE

O4 - HKLM\..\Run: [lhNEDwk6.exe] c:\winnt\temp\lhNEDwk6.exe

O4 - HKLM\..\Run: [3SM7FZ82J@J542] C:\WINNT\System32\JwhmnC.exe

O4 - HKLM\..\Run: [rF9O36Q] C:\WINNT\System32\brsndlg.exe

O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe

O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe

O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup

O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe

O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\tb_setup.exe /dcheck

O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe

O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\app20.tmp

O4 - HKLM\..\Run: [gxqxgxmc] C:\WINNT\System32\jcnamo.exe

O4 - HKLM\..\Run: [axroutef] C:\WINNT\System32\axroutef.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe

O4 - HKCU\..\Run: [Aaot] C:\Documents and Settings\ekalb.ED\Application Data\seda.exe

O4 - HKCU\..\Run: [WTSS] C:\WINNT\System32\wapicc.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: Toad.net Backup.lnk = C:\Program Files\Backup\sdbackup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe

O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.exe

O9 - Extra button: AOL Instant Messenger (SM) (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...ector/swdir.cab

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

O16 - DPF: {1FB464C8-09BB-4017-A2F5-EB742F04392F} (Microsoft Terminal Services Control (redist)) - http://terminator.toad.net/tsweb/mstscax.cab

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...76/mcinsctl.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2002121...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7585.5469675926

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = toad.net

O17 - HKLM\System\CCS\Services\Tcpip\..\{BFE69C91-CD65-4AF8-B07D-0AAC227EB950}: Domain = TOAD.NET

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = toad.net

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = toad.net

Share this post


Link to post
Share on other sites

Hi,

Download Peper trojan uninstaller: Newuninst.exe

http://downloads.subratam.org/Newuninst.exe

 

Double click on Newuninst.exe and press Uninstall.

Let it run and when the progress bar says complete, press Close.

You must be online to have this work and do not block any attempts for the program to connect to internet if your firewall requests access.

 

After the above reboot and then ...

 

Reconfigure Ad-Aware for Full Scan:

Please update the reference file following the instructions here:

http://www.lavahelp.com/howto/updref/index.html

 

Launch the program, and click on the Gear at the top of the start screen.

 

Click the "Scanning" button.

Under Drives & Folders, select "Scan within Archives".

Click "Click here to select Drives + folders" and select your installed hard drives.

 

Under Memory & Registry, select all options.

Click the "Advanced" button. Under "Log-file detail", select all options.

 

Click the "Tweaks" button. Under "Scanning Engine", select the following:

"Include additional Ad-aware settings in logfile" and

"Unload recognized processes during scanning."

Under "Cleaning Engine", select the following:

"Let Windows remove files in use after reboot."

Click on 'Proceed' to save these Preferences.

Please make sure that you activate IN-DEPTH scanning before you proceed.

 

After the above rescan with HijackThis and post a fresh log ...

Share this post


Link to post
Share on other sites

The new HJT log after performing instructed tasks is below. I rebooted as instructed (while connected) and had reoccurrence of spy/ad infestation. I have Mcafee AntiSpyware installed and it discovered several of the problems it always finds:

ISTBar

My Search

SideSearch

Weatherbug

WebRebates

and a new one - 2ndThought

 

IE was high jacked again - or attempted before it crashed disabling background video (desktop).

 

I believe the above listed problems are listed on my startup process in Win2000 Pro OS - how do you edit this process list so to remove them from startup?

 

Which running processes listed in the log are problems?

Thank you for your help!

 

Ed Kalb

Share this post


Link to post
Share on other sites

Hi,

The new HJT log after performing instructed tasks is below.

Did you forget the HijackThis log?

 

Note: the above tasks had nothing to do with what your McAfee is finding, I needed you to remove the Peper trojan first, then we can address the other issues. However I can't do that until I see a fresh log ...

 

it discovered several of the problems it always finds

If any of those are listed in Add Remove uninstall those, then reboot and then rescan with Hijack.

Share this post


Link to post
Share on other sites

Sorry for the omition... Here's the log. Thanks again for your time.

Ed Kalb

 

Logfile of HijackThis v1.97.7

Scan saved at 12:25:21 PM, on 6/24/2004

Platform: Windows 2000 SP3 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

 

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe

C:\WINNT\System32\svchost.exe

C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe

C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe

C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe

C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe

C:\Program Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe

C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\Explorer.EXE

C:\WINNT\System32\mspmspsv.exe

C:\WINNT\system32\svchost.exe

C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe

C:\WINNT\System32\tp4mon.exe

C:\WINNT\LTSMMSG.exe

C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe

C:\WINNT\System32\wuauclt.exe

C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe

C:\PROGRA~1\ACDSYS~1\ACDSEE\CAMDET~1.EXE

C:\PROGRA~1\mcafee.com\agent\mcagent.exe

C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe

C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe

C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe

C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

C:\installer\id53.exe

C:\Program Files\Web_Rebates\WebRebates0.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\Backup\sdbackup.exe

C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe

C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.exe

C:\Program Files\Web_Rebates\WebRebates1.exe

C:\Program Files\Lavasoft\HJT\HijackThis.exe

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe

O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe

O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe

O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\NeroCheck.exe

O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot

O4 - HKLM\..\Run: [Camera Detector] C:\PROGRA~1\ACDSYS~1\ACDSEE\CAMDET~1.EXE

O4 - HKLM\..\Run: [lhNEDwk6.exe] c:\winnt\temp\lhNEDwk6.exe

O4 - HKLM\..\Run: [rF9O36Q] C:\WINNT\System32\brsndlg.exe

O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe

O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe

O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe

O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup

O4 - HKLM\..\Run: [_AntiSpyware] C:\Program Files\McAfee\McAfee AntiSpyware\MssCli.exe

O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\tb_setup.exe /dcheck

O4 - HKLM\..\Run: [iRiver Updater] C:\Program Files\iRiver\iRiver Manager\Updater\Updater.exe

O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\app20.tmp

O4 - HKLM\..\Run: [axroutef] C:\WINNT\System32\axroutef.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe

O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

O4 - HKCU\..\Run: [Aaot] C:\Documents and Settings\ekalb.ED\Application Data\seda.exe

O4 - HKCU\..\Run: [WTSS] C:\WINNT\System32\wapicc.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - Global Startup: Toad.net Backup.lnk = C:\Program Files\Backup\sdbackup.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe

O4 - Global Startup: Wireless-G Notebook Adapter Utility.lnk = C:\Program Files\Linksys\Wireless-G Notebook Adapter\WPC54CFG.exe

O9 - Extra button: AOL Instant Messenger (SM) (HKLM)

O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa...ector/swdir.cab

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -

O16 - DPF: {1FB464C8-09BB-4017-A2F5-EB742F04392F} (Microsoft Terminal Services Control (redist)) - http://terminator.toad.net/tsweb/mstscax.cab

O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC...bin/AvSniff.cab

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...76/mcinsctl.cab

O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab

O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2002121...all/xscan53.cab

O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/...7585.5469675926

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa...ash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = toad.net

O17 - HKLM\System\CCS\Services\Tcpip\..\{BFE69C91-CD65-4AF8-B07D-0AAC227EB950}: Domain = TOAD.NET

O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = toad.net

O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = toad.net

Share this post


Link to post
Share on other sites

Hi,

First do a Purity (trojan) scan uninstall

http://www.purityscan.com/uninstall.html

 

Next thing to do is ...

 

Reconfigure Windows Explorer to show Hidden Files:

Open the Windows Explorer Folder Options - View [tab]:

 

Scroll down to the "Files and Folders" section.

Select: "Display the contents of system folders".

 

Scroll down to the "Hidden Files and Folders" section.

Select: "Show hidden files and folders", Ok the prompt

Uncheck: "Hide file extensions for known file types"

Uncheck: "Hide protected operating system files" Ok the Prompt, click Apply

 

Click the "Apply to all Folders" button. Close Windows Explorer.

 

Next:

 

Close all open windows, except for HijackThis place a check in each of the following:

Then click "Fix checked".

 

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R3 - URLSearchHook: (no name) - _{00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

R3 - URLSearchHook: (no name) - _{5D60FF48-95BE-4956-B4C6-6BB168A70310} - (no file)

O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file)

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [lhNEDwk6.exe] c:\winnt\temp\lhNEDwk6.exe

O4 - HKLM\..\Run: [rF9O36Q] C:\WINNT\System32\brsndlg.exe

O4 - HKLM\..\Run: [TB_setup] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\tb_setup.exe /dcheck

O4 - HKLM\..\Run: [Prein] C:\DOCUME~1\ekalb.ED\LOCALS~1\Temp\app20.tmp

O4 - HKLM\..\Run: [axroutef] C:\WINNT\System32\axroutef.exe

O4 - HKLM\..\Run: [stcinstaller] c:\installer\id53.exe

O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"

O4 - HKCU\..\Run: [Aaot] C:\Documents and Settings\ekalb.ED\Application Data\seda.exe

O4 - HKCU\..\Run: [WTSS] C:\WINNT\System32\wapicc.exe

 

Then reboot, on restart, restart in Safe Mode (see "How To" below)

 

Start | Run (type) "%temp%" (no quotes)

Completely delete the entire contents of that "temp" folder.

 

Next: Open Windows Explorer to: c:\winnt\temp

Completely delete the entire contents of that "temp" folder.

 

Open Windows Explorer locate and delete the following:

 

C:\installer <--this folder

C:\Program Files\Web_Rebates <--this folder

c:\winnt\temp\lhNEDwk6.exe <--this file

C:\WINNT\System32\brsndlg.exe <--this file

C:\WINNT\System32\axroutef.exe <--this file

C:\Documents and Settings\ekalb.ED\Application Data\seda.exe <--this file

C:\WINNT\System32\wapicc.exe <--this file

 

Restart normally and then ...

Rescan with Ad-Aware and SpyBot (make sure they are updated!)

Reboot after each scan ...

 

After the above Download > HijackThis 1.98

After the above, reboot, rescan with HijackThis 1.98 and post a fresh log ...

Edited by WinHelp2002

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0