I'm helping a friend to clean up a laptop.... no matter how many times i run spybot or ad-aware... Boran.g always comes back... so annoying...
Here's the PANDA report:
Incident Status Location
Adware:Adware/Wsearch Not disinfected C:\FOUND.008\FILE0003.CHK
Adware:Adware/NCast Not disinfected C:\WINDOWS\system32\drivers\sispc.sys
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\drivers\Albus.SYS
Hacktool:Rootkit/Hidport Not disinfected C:\WINDOWS\system32\drivers\hidport.sys
Virus:Bck/Irjit.B Disinfected C:\WINDOWS\system32\wbem\zeocgb66.dll
Virus:Trj/Downloader.KHR Disinfected C:\WINDOWS\system32\enup32.dll
Adware:Adware/MMediapd Not disinfected C:\WINDOWS\system32\ext\dtdl.dll
Adware:adware/mmediapd Not disinfected C:\WINDOWS\system32\ext\dtsm.dll
Adware:Adware/BaiduBar Not disinfected C:\WINDOWS\system32\A4SOFT\baisod\dllhostd.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\alsmt.exe
Adware:Adware/KooWo Not disinfected C:\WINDOWS\system32\YHBO.dll
Possible Virus. Not disinfected C:\WINDOWS\system32\wmpes.ini
Possible Virus. Not disinfected C:\WINDOWS\system32\SPOOLS.EXE
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\albus.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\stdupnet.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\stdstub.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\stdvote.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\stdplay.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\system32\jetspeed.dll
Adware:Adware/Ourxin Not disinfected C:\WINDOWS\system32\msicn\ube.exe
Adware:Adware/Ourxin Not disinfected C:\WINDOWS\system32\1116\ntjdo\vcf.fyf
Adware:Adware/NewWeb Not disinfected C:\WINDOWS\system32\Inte32.dll
Adware:Adware/Simfly Not disinfected C:\WINDOWS\system32\sys32version.dll
Adware:Adware/LinkMedia Not disinfected C:\WINDOWS\system32\ACSs.dll
Adware:Adware/NewWeb Not disinfected C:\WINDOWS\system32\Inte.dll
Adware:Adware/LinkMedia Not disinfected C:\WINDOWS\system32\Nwsapagent.dll
Adware:Adware/LinkMedia Not disinfected C:\WINDOWS\system32\sdmAgent20.dll
Adware:Adware/LinkMedia Not disinfected C:\WINDOWS\system32\sdmAgent22.dll
Adware:Adware/BaiduBar Not disinfected C:\WINDOWS\system32\zsSOFT\baisof\dllhostf.dll
Adware:Adware/NewWeb Not disinfected C:\WINDOWS\system\vp_VM.dll
Adware:Adware/LinkMedia Not disinfected C:\WINDOWS\Temp\sdmagent.exe[sdmAgent22.dll]
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\cheung@ad.yieldmanager[1].txt
Adware:Adware/Borlander Not disinfected C:\WINDOWS\Temp\insshell\insshell.exe
Adware:Adware/IconAds Not disinfected C:\WINDOWS\Temp\exupstd\setup.exe
Adware:Adware/Borlander Not disinfected C:\WINDOWS\Temp\insmms5\setup.exe[albus.dll]
Adware:Adware/Borlander Not disinfected C:\WINDOWS\Temp\insmms5\setup.exe[2eC]
Adware:Adware/Borlander Not disinfected C:\WINDOWS\webwork\webwork.dll
Adware:Adware/Borlander Not disinfected C:\WINDOWS\webwork\webwork.nls
Possible Virus. Not disinfected C:\WINDOWS\mTmp.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update8.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update13.exe
Adware:Adware/CommAd Not disinfected C:\WINDOWS\Y2hldW5n\sZ15xqcB.vbs
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update18.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update19.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update20.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update22.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update21.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update23.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update24.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update25.exe
Adware:Adware/AdHelper Not disinfected C:\WINDOWS\update26.exe
Spyware:Spyware/Iehelp Not disinfected C:\Documents and Settings\All Users\Application Data\Microsoft\UserData\IEHelper_5025.dll
Virus:Bck/Irjit.B Disinfected C:\Documents and Settings\All Users\Templates\temp.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00800500.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01742118.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04895246.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03295188.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00642001.exe
Possible Virus. Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\xp83.tmp.exe
Adware:Adware/KooWo Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\rg_lyric_014.exe[YHBO.dll]
Adware:Adware/KooWo Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\rg_lyric_014.exe[HTTPDll.dll]
Adware:Adware/KooWo Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\rg_lyric_014.exe[lrcsys.exe]
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00870451.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03088337.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03082938.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01807114.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00819806.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\setup.exe
Adware:Adware/LinkMedia Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\lmdm_setup_2.1_102.exe[ACSs.dll]
Adware:Adware/LinkMedia Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\lmdm_setup_2.1_102.exe[Nwsapagent.dll]
Adware:Adware/LinkMedia Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\lmdm_setup_2.1_102.exe[sdmAgent20.dll]
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02680022.exe
Spyware:Spyware/Iehelp Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\5025.exe
Adware:Adware/ActiveSearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\Setup_YH0017.exe
Adware:Adware/ISearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\b104.exe[MTE3MTk6ODoxNg.exe]
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\b104.exe[2UC\nsRandom.dll]
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04367547.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04742694.exe
Adware:Adware/BaiduBar Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\potti.exe[BaiduBar.dll]
Adware:Adware/BaiduBar Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\5344.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\b116.exe
Adware:Adware/EliteBar Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\b111.exe
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\wd2_051117_NAV062_mini.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\wd2_051117_NAV062_mini.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\wd2_051117_NAV062_mini.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\secp.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\secp.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\secp.exe[2eC]
Adware:Adware/Ourxin Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\secp.exe[2eC]
Possible Virus. Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\up26.exe
Virus:Trj/Downloader.KVF Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\tubar1230.exe[HttpGetyuletx.exe]
Adware:Adware/Mytoolbar Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\tubar1230.exe[HttpGet.exe]
Virus:Trj/Multidropper.BOU Disinfected C:\Documents and Settings\cheung\Local Settings\Temp\hc01.exe
Adware:Adware/Borlander Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\insshell\insshell.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00588103.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02761675.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02648279.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01065660.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04205847.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03516531.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04743943.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00206001.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02420470.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01500112.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01102411.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02862227.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02318828.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\02225829.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00868055.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04484692.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\00236403.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04117442.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01716017.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01289814.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03811034.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03419438.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04227893.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01516160.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04438043.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\01090213.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04814197.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\03211736.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04522291.exe
Adware:Adware/Wsearch Not disinfected C:\Documents and Settings\cheung\Local Settings\Temp\04766397.exe
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\cheung\Cookies\cheung@xiti[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\cheung\Cookies\cheung@searchportal.information[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\cheung\Cookies\cheung@com[1].txt
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{38E9DE2F-06C5-1028-0902-050507060354}\Uninst.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinAdmin.exe
Adware:Adware/YazzleSudoku Not disinfected C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
Adware:Adware/DollarRevenue Not disinfected C:\Program Files\Common Files\{38E9DE2F-06C5-3076-0902-050507060354}\Uninst.exe
Possible Virus. Not disinfected C:\Program Files\Ringz Studio\Storm Codec\StormSet.exe[zcomcli_sc.exe]
Adware:Adware/Borlander Not disinfected C:\Program Files\MMSAssist\Mmsass~1.dll
Adware:Adware/Borlander Not disinfected C:\Program Files\MMSAssist\albus.dll
Adware:Adware/Borlander Not disinfected C:\Program Files\MMSAssist\mmssver.dll
Adware:Adware/Simfly Not disinfected C:\temp\3748.exe
Possible Virus. Not disinfected C:\temp\bind_40127.exe
Adware:Adware/Eztracks Not disinfected C:\temp\SearchBar.exe[SearchBar.dll]
Possible Virus. Not disinfected D:\System Volume Information\_restore{C1F8D83E-EC09-4E58-8B1F-FE578F91939E}\RP311\A0056447.exe
Possible Virus. Not disinfected D:\System Volume Information\_restore{C1F8D83E-EC09-4E58-8B1F-FE578F91939E}\RP323\A0058388.exe
Possible Virus. Not disinfected D:\System Volume Information\_restore{C1F8D83E-EC09-4E58-8B1F-FE578F91939E}\RP323\A0059505.exe
Possible Virus. Not disinfected D:\System Volume Information\_restore{C1F8D83E-EC09-4E58-8B1F-FE578F91939E}\RP323\A0059506.exe
Possible Virus. Not disinfected D:\System Volume Information\_restore{C1F8D83E-EC09-4E58-8B1F-FE578F91939E}\RP326\A0061317.exe
hijackthis will be posted next...