smitRembeta

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

sigriff

Thread Starter
Joined
Jul 12, 2005
Messages
4
Hello mister tech guy I can't seem to find the smitRembeta file to be able to clear my computer of this stealthSWs114. If it needs to be within 48hrs of reciept of the virus then I'm runnig out of time. Please help this virus is driving me mad. I have followed the instrutions but forgot to download the smitRembeta file, all i need to do is find the file to be able to complete the process.

Thanks very much,
Simon

p.s. i'm glad nice people like you exsit to help people like me

Logfile of HijackThis v1.99.1
Scan saved at 00:02:33, on 13/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\shnlog.exe
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\system32\intmon.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Program Files\WinMX\WinMX.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\BigFix\BigFix.exe
C:\pics\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\ScsiAccess.EXE
C:\WINDOWS\system32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\BT Broadband Help\bin\mpbtn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicksearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.oneclicksearches.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicksearches.com/search.php?qq=%1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.msn.co.uk
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicksearches.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicksearches.com/search.php?qq=%1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicksearches.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\system32\hp7222.tmp
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing)
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MskDetct.exe /startup
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 205 ADSL Router\Adsl\dslagent.exe
O4 - HKLM\..\Run: [GSISETUP] C:\DOCUME~1\SP-G\LOCALS~1\Temp\GsiInst.exe INSTALL C:\DOCUME~1\SP-G\LOCALS~1\Temp\.\V205Res 13
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\BTBROA~2\SMARTB~1\BTHelpNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband Help\bin\matcli.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\pics\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\Program Files\McAfee\Anti-Phishing Filter\McAfeeAntiPhishingBHO.dll
O9 - Extra 'Tools' menuitem: McAfee Anti-Phishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - C:\Program Files\McAfee\Anti-Phishing Filter\McAfeeAntiPhishingBHO.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.msn.co.uk
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\system32\ScsiAccess.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
120,232
Hi and welcome to TSG,

Please do this. Click here to download HijackThis.

Close all open windows and open HijackThis. Click “Scan”. When the scan is finished, the scan button will change to “Save Log”. Click on “Save Log” and then save it to Notepad. Click on “Edit” – “Select all” – “copy” and then “paste” into the thread.

DO NOT FIX ANYTHING YET, most items that appear in the log are harmless or even needed.
 
Joined
Sep 7, 2004
Messages
49,014
You should have posted the log in the new reply - Cookie will get u fixed the removal you did didn't take - make sure you follow cookies directions to the letter.
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
120,232
You need to uninstall WinMx or you will always be plagued with problems. Uninstall it via the control panel.

Click here to download smitRem.zip.
  • Save the file to your desktop.
  • Unzip smitRem.zip to extract the files it contains.
  • Do not do anything with it yet. You will run the RunThis.bat file later in safe mode.


Go here to download CCleaner.
  • Install CCleaner
  • Launch CCleaner and look in the upper right corner and click on the Options button.
  • Click Advanced and remove the check by Only delete files in Windows temp folders older than 48 hours.
  • Click OK
  • Do not run CCleaner yet. You will run it later in safe mode.


Click here to download Killbox and save it to your desktop.


Download the trial version of Ewido Security Suite here.
  • Install Ewido.
  • During the installation, under Additional Optionsuncheck[ b]Install background guard[/b] and Install scan via context menu.
  • Launch Ewido
  • It will prompt you to update click the OK button and it will go to the main screen
  • On the left side of the main screen click update
  • Click on Start and let it update.
  • DO NOT run a scan yet. You will do that later in safe mode.


Click here for info on how to boot to safe mode.


Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.


Restart your computer into safe mode now. Perform the following steps in safe mode:


Now go ahead and set your computer to show hidden files like so:

Go to Start – Search and under More advanced search options, make sure there is a check by Search System Folders and Search hidden files and folders and Search system subfolders.

Next, click on My Computer, Go to Tools – Folder Options. Click on the View tab and make sure that Show hidden files and folders is checked. Also uncheck Hide protected operating system files and Hide extensions for known file types. Now click Apply to all folders. Click Apply and then OK.



Run HijackThis again and put a check by these. Close ALL windows except HijackThis and click Fix checked



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.oneclicksearches.com/bar.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.oneclicksearches.com/search.php?qq=%1

R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.oneclicksearches.com/search.php?qq=%1

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.oneclicksearches.com/search.php?qq=%1

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.oneclicksearches.com/

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

F2 - REG:system.ini: Shell=Explorer.exe, msmsgs.exe

O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFA} - C:\WINDOWS\system32\hp7222.tmp

O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll (file missing)

O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [GSISETUP] C:\DOCUME~1\SP-G\LOCALS~1\Temp\GsiInst.exe INSTALL C:\DOCUME~1\SP-G\LOCALS~1\Temp\.\V205Res 13

O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe




Double-click on Killbox.exe to run it. Now put a tick by Standard File Kill. In the Full Path of File to Delete box, copy and paste each of the following lines one at a time then click on the button that has the red circle with the X in the middle after you enter each file. It will ask for confirmation to delete the file. Click Yes. Continue with that same procedure until you have copied and pasted all of these in the Paste Full Path of File to Delete box.

C:\WINDOWS\system32\msmsgs.exe

C:\WINDOWS\system32\hp7222.tmp

C:\WINDOWS\system32\ShowWnd.exe

C:\DOCUME~1\SP-G\LOCALS~1\Temp\GsiInst.exe INSTALL

C:\DOCUME~1\SP-G\LOCALS~1\Temp\.\V205Res 13

C:\Program Files\WinMX\WinMX.exe


Note: It is possible that Killbox will tell you that one or more files do not exist. If that happens, just continue on with all the files. Be sure not to miss any.

Exit the Killbox.


Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.

Wait for the tool to complete and disk cleanup to finish.


* Run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan it will prompt you to clean files, click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop

Start CCleaner and click Run Cleaner


Go to Control Panel – Internet Options. Click on the Programstab then click the Reset Web Settings button. Click Apply then OK.


Next go to Control Panel – Display. Click on the Desktop tab then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see an entry checked called something like Security info or similar. If it is there, select that entry and click the Delete button. Click OK then Apply and OK.


Restart back into Windows normally now.


Run ActiveScan online virus scan here

When the scan is finished, have it delete anything that it cannot clean. Make a note of the file location of anything that cannot be deleted so you can delete it yourself. - Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan and the Ewido scan
 

sigriff

Thread Starter
Joined
Jul 12, 2005
Messages
4
Thanks for all your help with getting rid of "stealthSWs114". When I ran Ewido there were some files or viruses that it could not get rid of. Thanks anyway and here are the scan results.


Incident Status Location
Adware:Adware/CWS No disinfected C:\Documents and Settings\SP-G\Favorites\Online Gambling\Online Gambling.url
Spyware:Spyware/Dluca No disinfected Windows Registry
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Black Jack Online.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Adipex.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Black Jack Online.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Home Loan.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Network Security.url
Adware:Adware/CWS No disinfected C:\Documents and Settings\SP-G\Favorites\Online Gambling\Online Gambling.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Online Gambling.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Adipex.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Alprazolam.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Carisoprodol.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Diazepam.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Hydrocodone.url
Adware:Adware/CWS No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Lortab.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Online Pharmacy.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Prozac.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Valium.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Vicodin.url
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy\Xanax.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Online Pharmacy.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Spam Filters.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Take It Here - Free Porn TGP.url
Adware:Adware/Popuper No disinfected C:\Documents and Settings\SP-G\Favorites\Web Detective.url

ANALYSIS COMPLETE - (8.092 secs)
------------------------------------------------------------------------------------------
11.9MB to be removed. (Approximate size)


Details of files to be deleted (Note: No files have been deleted yet)
------------------------------------------------------------------------------------------
IE Temporary Internet Files (510 files) 7.36MB
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 448 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][2].txt 95 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][2].txt 148 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 95 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 97 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 139 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 79 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][2].txt 199 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected]o[2].txt 103 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 340 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 102 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][2].txt 290 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 138 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 349 bytes
C:\Documents and Settings\SP-G\Cookies\[email protected][1].txt 86 bytes
C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\desktop.ini 113 bytes
C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\MSHist012005071120050718\index.dat 80.00KB
C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\MSHist012005071720050718\index.dat 48.00KB
C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\MSHist012005071820050719\index.dat 0.14MB
C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\MSHist012005071920050720\index.dat 48.00KB
Marked for deletion: C:\Documents and Settings\SP-G\Local Settings\Temporary Internet Files\Content.IE5\index.dat
Marked for deletion: C:\Documents and Settings\SP-G\Cookies\index.dat
Marked for deletion: C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\index.dat
Marked for deletion: C:\Documents and Settings\SP-G\Local Settings\History\History.IE5\mshist012005071720050718\index.dat
C:\WINDOWS\TEMP\Cookies\index.dat 16.00KB
C:\WINDOWS\TEMP\History\History.IE5\desktop.ini 113 bytes
C:\WINDOWS\TEMP\History\History.IE5\index.dat 32.00KB
C:\WINDOWS\TEMP\mcu4.tmp\McAppIns.exe 0.13MB
C:\WINDOWS\TEMP\mcu4.tmp\UpdReq.mcaf 1.31KB
C:\WINDOWS\TEMP\mcu4.tmp\UpdResp.mcaf 771 bytes
C:\WINDOWS\TEMP\mcu5.tmp\McAppIns.exe 0.13MB
C:\WINDOWS\TEMP\mcu5.tmp\UpdReq.mcaf 1.31KB
C:\WINDOWS\TEMP\mcu5.tmp\UpdResp.mcaf 771 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\2482UPG9\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\CH2V09EV\CAHH6XZK.lpk 1.80KB
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\CH2V09EV\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat 32.00KB
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\KTY7OH2N\desktop.ini 67 bytes
C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\VFBL3VY4\desktop.ini 67 bytes
C:\DOCUME~1\SP-G\LOCALS~1\Temp\3.3.61.28-EasyShrx.Dll 92.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\bbassistant.log 2.55KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR10.tmp 34.74KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR11.tmp 9.99KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR13F.tmp 37.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR140.tmp 66.40KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR144.tmp 34.74KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR145.tmp 9.99KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR147.tmp 61.28KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR14D.tmp 22.88KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR152.tmp 20.63KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR157.tmp 22.72KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR15F.tmp 44.94KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR16.tmp 61.28KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR1B.tmp 22.88KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR26.tmp 20.63KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFR29.tmp 22.72KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFRE.tmp 37.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\TFRF.tmp 66.40KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF19C5.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF1EB2.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF3B63.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF63B1.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF72D.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF7AAA.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DF951F.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFB88D.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFE026.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFF3EC.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFF40A.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFF89F.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFFDFD.tmp 32.00KB
C:\DOCUME~1\SP-G\LOCALS~1\Temp\~DFFFFE.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\3.3.61.28-EasyShrx.Dll 92.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\bbassistant.log 2.55KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR10.tmp 34.74KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR11.tmp 9.99KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR13F.tmp 37.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR140.tmp 66.40KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR144.tmp 34.74KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR145.tmp 9.99KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR147.tmp 61.28KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR14D.tmp 22.88KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR152.tmp 20.63KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR157.tmp 22.72KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR15F.tmp 44.94KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR16.tmp 61.28KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR1B.tmp 22.88KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR26.tmp 20.63KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFR29.tmp 22.72KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFRE.tmp 37.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\TFRF.tmp 66.40KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF19C5.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF1EB2.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF3B63.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF63B1.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF72D.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF7AAA.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DF951F.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFB88D.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFE026.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFF3EC.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFF40A.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFF89F.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFFDFD.tmp 32.00KB
C:\Documents and Settings\SP-G\Local Settings\Temp\~DFFFFE.tmp 32.00KB
C:\WINDOWS\system32\wbem\Logs\wbemess.log 20.52KB
C:\WINDOWS\system32\wbem\Logs\wmiprov.log 878 bytes
C:\WINDOWS\system32\wbem\Logs\wbemess.lo_ 64.03KB
C:\WINDOWS\0.log 0 bytes
C:\WINDOWS\comsetup.log 46.14KB
C:\WINDOWS\FaxSetup.log 0.14MB
C:\WINDOWS\iis6.log 22.27KB
C:\WINDOWS\imsins.log 1.34KB
C:\WINDOWS\KB873333.log 16.27KB
C:\WINDOWS\KB873339.log 20.07KB
C:\WINDOWS\KB883939.log 22.14KB
C:\WINDOWS\KB885250.log 20.65KB
C:\WINDOWS\KB885835.log 20.72KB
C:\WINDOWS\KB885836.log 19.78KB
C:\WINDOWS\KB886185.log 9.13KB
C:\WINDOWS\KB887742.log 20.76KB
C:\WINDOWS\KB888113.log 20.09KB
C:\WINDOWS\KB888302.log 14.16KB
C:\WINDOWS\KB890046.log 17.29KB
C:\WINDOWS\KB890175.log 19.88KB
C:\WINDOWS\KB890859.log 16.36KB
C:\WINDOWS\KB891781.log 16.23KB
C:\WINDOWS\KB893066.log 16.71KB
C:\WINDOWS\KB893086.log 14.82KB
C:\WINDOWS\KB893803v2.log 9.34KB
C:\WINDOWS\KB896358.log 17.24KB
C:\WINDOWS\KB896422.log 20.94KB
C:\WINDOWS\KB896428.log 12.26KB
C:\WINDOWS\KB898461.log 10.64KB
C:\WINDOWS\KB901214.log 14.83KB
C:\WINDOWS\KB903235.log 7.59KB
C:\WINDOWS\msgsocm.log 6.94KB
C:\WINDOWS\ntdtcsetup.log 28.03KB
C:\WINDOWS\ocgen.log 65.50KB
C:\WINDOWS\ocmsn.log 7.68KB
C:\WINDOWS\setupact.log 0 bytes
C:\WINDOWS\setupapi.log 93.02KB
C:\WINDOWS\setuperr.log 0 bytes
C:\WINDOWS\tsoc.log 52.99KB
C:\WINDOWS\updspapi.log 5.12KB
C:\WINDOWS\vminst.log 2.02KB
C:\WINDOWS\imsins.BAK 1.34KB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\drwtsn32.log 0.63MB
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp 74.78KB
C:\WINDOWS\Debug\mrt.log 730 bytes
C:\WINDOWS\security\logs\scecomp.old 4.07KB
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\#SharedObjects\EX5KP8AW\miniclip.com\gamefiles0304\bushroyalrampage.swf\MiniclipHighscores.sol 56 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\#SharedObjects\EX5KP8AW\miniclip.com\gamefiles0304\bushroyalrampage.swf\MiniclipLoaderAd.sol 60 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\#SharedObjects\EX5KP8AW\miniclip.com\swfcontent\push\rotator.swf\MiniclipFeaturedGame.sol 64 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\#SharedObjects\EX5KP8AW\naiadsystems.com\flash\generic\freechat.swf\naiad.sol 72 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#atomfilms.com\settings.sol 83 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#foxtvdvd.co.uk\settings.sol 84 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#miniclip.com\settings.sol 82 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#naiadsystems.com\settings.sol 86 bytes
C:\Documents and Settings\SP-G\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol 402 bytes
C:\Documents and Settings\SP-G\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\dstarbattle.jar-7898a1a8-239d805b.idx 173 bytes
C:\Documents and Settings\SP-G\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\dstarbattle.jar-7898a1a8-239d805b.zip 64.66KB
C:\Program Files\Microsoft AntiSpyware\errors.log 0 bytes
--------------------------------------------------------------------------

This doesn't mean anything to me but hopefully I've posted everthing you need our want from this. I hope this means that my computer is ok now. Thanks once again S
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
120,232
Navigate to this folder:

C:\Documents and Settings\SP-G\Favorites

and delete all of the entries listed in the Panda scan.

Also, please post your Hijack This log as requested.
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Members online

Top