1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

HELP I have a problem

Discussion in 'Virus & Other Malware Removal' started by deck20, Feb 2, 2005.

Thread Status:
Not open for further replies.
Advertisement
  1. deck20

    deck20 Thread Starter

    Joined:
    Feb 2, 2005
    Messages:
    16
    I didn't know where to post this plus I'm in a rush so here goes nothing hope you all can help me everytime I go to this site I keep getting an error saying:

    Server is busy try later and only this site

    this is the site

    www.rapsearch.com/board

    can you help please be able to!
     
  2. mjack547

    mjack547 Malware Specialist

    Joined:
    Sep 1, 2003
    Messages:
    3,181
    Welcome to TSG deck20

    I tried your site and got in with no problems.

    Go to http://majorgeeks.com/download3155.html and download 'Hijack This!'.

    First make a folder on your computer in my documents called Hijackthis and then Unzip it to that folder.
    Then doubleclick the Hijackthis.exe.

    Click the "Scan" button, when the scan is finished the scan button will become "Save Log" click that and save the log.
    Go to where you saved the log and click on "Edit > Select All" then click on "Edit > Copy" then Paste the log back here in a reply.
    It will possibly show issues deserving our attention, but most of what it lists will be harmless or even required,
    so do NOT fix anything yet.

    Someone here will be happy to help you analyze the results.
     
  3. deck20

    deck20 Thread Starter

    Joined:
    Feb 2, 2005
    Messages:
    16
    Logfile of HijackThis v1.99.0
    Scan saved at 1:11:47 PM, on 2/2/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\System32\ScsiAccess.EXE
    C:\WINDOWS\System32\tcpsvcs.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\System32\fmstji.exe
    C:\WINDOWS\wlirgcal.exe
    C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
    C:\WINDOWS\system32\sndcfg16.exe
    C:\Program Files\ISTsvc\istsvc.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
    C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
    C:\Program Files\BullsEye Network\bin\bargains.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Sedecka Griffin\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://webmail.pas.earthlink.net/wam/login.jsp?redirect=/wam/index.jsp?x=-18498999&x=1501183815
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://start.earthlink.net/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8081
    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: (no name) - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
    O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~2\SEARCH~1.DLL
    O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: SafeGuard Protect PCShield - {564FFB73-9EEF-4969-92FA-5FC4A92E2C2A} - C:\WINDOWS\System32\sfg_711a.dll
    O2 - BHO: BAHelper Class - {A3FDD654-A057-4971-9844-4ED8E67DBBB8} - C:\Program Files\SideFind\sfbho13.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\system32\msbe.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O4 - HKLM\..\Run: [vqialnqofqedn] C:\WINDOWS\System32\fmstji.exe
    O4 - HKLM\..\Run: [WakvfoUX] C:\WINDOWS\wlirgcal.exe
    O4 - HKLM\..\Run: [Propel Accelerator] C:\Program Files\EarthLink TotalAccess\Accelerator\PropelAC.exe
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKLM\..\Run: [WinProfile] sndcfg16.exe
    O4 - HKLM\..\Run: [IST Service] C:\Program Files\ISTsvc\istsvc.exe
    O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
    O4 - HKLM\..\RunServices: [WinProfile] sndcfg16.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
    O4 - Startup: FriendFinder Messenger.lnk = C:\Program Files\FriendFinder Messenger\FriendFinder Messenger\FFIMC.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
    O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
    O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
    O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Program Files\SideFind\sidefind13.dll
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
    O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
    O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/DownloadsUnlimited/ie/bridge-c9.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{AE2A675C-5A41-4EF6-AB23-F42163ED6CB6}: NameServer = 207.69.188.187 207.69.188.186
    O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: GoToMyPC - Expertcity - C:\Program Files\Expertcity\GoToMyPC\g2svc.exe
    O23 - Service: Kodak Camera Connection Software - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: ScsiAccess - Unknown - C:\WINDOWS\System32\ScsiAccess.EXE
    O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe
     
  4. mjack547

    mjack547 Malware Specialist

    Joined:
    Sep 1, 2003
    Messages:
    3,181
    Go to control panel, add/remove programs and remove these

    BullseyeNetwork

    Web Rebates - Web Offer - rebate nation -Ezula - TV MEDIA


    Than

    Run an online antivirus check from at least one and preferably 2 of the following sites

    http://security.symantec.com/default.asp?
    http://housecall.trendmicro.com/
    http://www.pandasoftware.com/activescan/
    http://www.ravantivirus.com/scan/
    http://www.anti-trojan.net/en/onlinecheck.aspx



    Be sure and put a check in the box by "Auto Clean" before you do the
    scan. If it finds anything that it cannot clean have it delete it or
    make a note of the exact file name and file location so you can delete it yourself.

    Reboot and post a new hijackthis log
     
  5. deck20

    deck20 Thread Starter

    Joined:
    Feb 2, 2005
    Messages:
    16
    Ok I'm have 101 file infected what do i do?

    these are the files


    4353 files scanned, 101 file(s) infected on your disk drives.


    No viruses were detected in memory.

    Your computer is free of known viruses and Trojan horses. Virus Detection does not check compressed files.

    Your computer appears safe for now. If you want to protect your computer from viruses, hackers and privacy threats, upgrade to Norton Internet Security¬ô.

    No viruses were detected in memory.

    The scan was cancelled before finishing. To restart the scan, click here.

    Your computer is free of known viruses and Trojan horses. Virus Detection does not check compressed files.

    Your computer appears safe for now. If you want to protect your computer from viruses, hackers and privacy threats, upgrade to Norton Internet Security¬ô.

    Warning! The scan detected a virus that is active in your computer's memory.
    The scan ended to prevent further infection.

    You should shut down your computer immediately and restart it with an antivirus rescue disk or similar tool.


    No viruses were detected in memory.

    Your computer is infected with at least one known virus or Trojan horse.

    Search for the name of the virus(s) listed below on the Symantec Security Response site for removal information.


    No viruses were detected in memory.

    Your computer is infected with at least one known virus or Trojan horse.

    Note: The scan was cancelled before finishing. There may be more infected files on this computer.

    Search for the name of the virus(s) listed below on the Symantec Security Response site for removal information.


    A scan has not been run. To start Virus Detection, click here.

    C:\WINDOWS\system32\sndcfg16.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Ad-aware Pro Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Acrobat Reader crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Golive v6.0 Keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Illustrator v10.0 Time Limit Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe ImageReady v1.0 crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe PageMaker v7.0 Keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Photoshop 7 keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Photoshop all.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Adobe Serial Generator v2.0.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Age of Empires II The Age of Kings NO CD crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Age Of Mythology - The Titans no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Age Of Mythology no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Alias Acclaim crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\All Macromedia Products Keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Anti-Trojan 4.0.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Avant Browser.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Backyard Baseball 2003 no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Backyard Wrestling 2 - There Goes the Neighborhood Eidos Interactive crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Battlefield 1942 no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Battlefield Vietnam EA Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Battlefield Vietnam Multiplayer Online Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Besieger Strategy DreamCatcher Interactive crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Blinx 2 - Masters of Time & Space Microsoft crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Blitzkrieg - Burning Horizon Strategy CDV Software GmbH crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Call of Duty Activision crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Call Of Duty no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\City of Heroes Role-Playing NCsoft crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Civilization III crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Classic NES Series - The Legend of Zelda GBA Role-Playing Nintendo crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\CloneDVD v1.x crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Command & Conquer - Generals no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Command & Conquer - Generals Zero Hour no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Command & Conquer - Generals Zero Hour Strategy EA Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Counter-Strike Condition Zero Keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Credit card generator.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Crusader Kings Strategy Paradox Entertainment crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Cubase Audio XT 3.X crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dark Age Of Camelot - Trials Of Atlantis no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dark Matter - The Baryon Proj crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Deus Ex Invisible War NO CD Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Diablo 2 no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\DivX Player and Codec.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Doom 3 Activision crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Doom 3 NO CD Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Download Accelerator Plus (spyware free).exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dragon Ball Z - Budokai 3 Atari crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dragon Ball Z - Supersonic Warriors GBA Atari crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dragon Warrior VIII Role-Playing Square Enix crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\DRIV3R Atari crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dungeon Lords Role-Playing DreamCatcher Interactive crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Dungeon Siege no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Enter the Matrix Atari crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\ESPN NFL 2K5 Sega crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\F.E.A.R. VU Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Fable Role-Playing Microsoft crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Far Cry Ubisoft crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Final Fantasy VII - Advent Children PSP Role-Playing Square Enix crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Final Fantasy XI - Square Enix USA no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Final Fantasy XII Role-Playing Square Enix crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Fire Emblem - Seima no Kouseki GBA Role-Playing Nintendo crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP 2 RC2 Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP v1.4.1 Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP v1.4.3 Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP v2.0 Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP v2.1 crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashFXP v2.2 crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\FlashGet.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Forgotten Realms - Demon Stone Atari crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Forgotten Realms - Demon Stone crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Freedom Force no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Front Mission 4 Strategy Square Enix crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Full Spectrum Warrior Strategy THQ crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Geist GC Nintendo crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Goblin Commander - Unleash the Horde Strategy Jaleco Entertainment crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Gran Turismo 4 SCEA crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Grand Theft Auto - San Andreas Rockstar Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Grand Theft Auto 3 no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Grand Theft Auto III no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Grand Theft Auto San Andreas NO CD crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Grand Theft Auto Vice City NO CD crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\GTA crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Half-Life 2 Keygen.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Half-Life 2 NO CD Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Half-Life 2 VU Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Halo - Combat Evolved - Microsoft no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Halo 2 crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Harry Potter & The Sorcerers Stone no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Harry Potter and the Prisoner of Azkaban Adventure EA Games crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Harry Potter and the Sorcerers Stone no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Heroes of Might & Magic IV no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Hidden & Dangerous 2 NO CD Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Icewind Dale 2 no cd crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\ICQ 4.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\ICQ Pro 2003b.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\iMesh patch.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Jedi Academy NO CD Crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Joint Operations - Typhoon Rising NovaLogic crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Juiced Acclaim crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Kingdom Hearts II Role-Playing Square Enix crack.exe is infected with W32.IRCBot
    C:\WINDOWS\SoftwareDistribution\Download\Knights Apprentice Memoricks Adventures Games crack.exe is infected with W32.IRCBot
     
  6. mjack547

    mjack547 Malware Specialist

    Joined:
    Sep 1, 2003
    Messages:
    3,181
    Did you do the online scan and check the box for auto clean?
     
  7. deck20

    deck20 Thread Starter

    Joined:
    Feb 2, 2005
    Messages:
    16
    ok I did that but what if some of the files are in use and I don't know how to turn them off what do I do, plus as the I delete files with the scanners all the files that I delete keep popping back up in different locations
     
  8. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/325946

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice