Hi, I've been volunteered to fix a friends computer as they had a few problems with it.
It appears as though they had a desktop hijacker - which pointed IE to www.securitycenter.com, which I believe I have at least partially removed, although not completely.
After seeing this, I ran a pc-cillin scan to discover it suggested that TROJ_ZLOB.ZW was on the pc within a file called mssearchnet.exe in c:\windows\system32\. This I looked up on the trend housecall website, and followed their instructions on removal - which obviously haven't worked.
I have run an online Panda Software Active Scan with the following results:
Incident Status Location
Virus:Trj/Downloader.IHX Disinfected Operating system
Possible Virus. Not disinfected C:\WINDOWS\system32\hp86DE.tmp
Adware:adware/emediacodec Not disinfected C:\WINDOWS\system32\nvctrl.exe
Adware:adware/emediacodec Not disinfected C:\WINDOWS\SYSTEM32\dfrgsrv.exe
Adware:adware/securityerror Not disinfected C:\WINDOWS\SYSTEM32\ot.ico
Adware:adware/cws Not disinfected C:\WINDOWS\SYSTEM32\paytime.exe
Adware:adware/secure32 Not disinfected C:\WINDOWS\SYSTEM32\scmt16.exe
Adware:adware/spywarequake Not disinfected C:\WINDOWS\SYSTEM32\stickrep.dll
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\ms1.exe
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.atwola.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[ad.sensismediasmart.com.au/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Match Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[promo.match.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Bonnie\Application
Cont'd...
It appears as though they had a desktop hijacker - which pointed IE to www.securitycenter.com, which I believe I have at least partially removed, although not completely.
After seeing this, I ran a pc-cillin scan to discover it suggested that TROJ_ZLOB.ZW was on the pc within a file called mssearchnet.exe in c:\windows\system32\. This I looked up on the trend housecall website, and followed their instructions on removal - which obviously haven't worked.
I have run an online Panda Software Active Scan with the following results:
Incident Status Location
Virus:Trj/Downloader.IHX Disinfected Operating system
Possible Virus. Not disinfected C:\WINDOWS\system32\hp86DE.tmp
Adware:adware/emediacodec Not disinfected C:\WINDOWS\system32\nvctrl.exe
Adware:adware/emediacodec Not disinfected C:\WINDOWS\SYSTEM32\dfrgsrv.exe
Adware:adware/securityerror Not disinfected C:\WINDOWS\SYSTEM32\ot.ico
Adware:adware/cws Not disinfected C:\WINDOWS\SYSTEM32\paytime.exe
Adware:adware/secure32 Not disinfected C:\WINDOWS\SYSTEM32\scmt16.exe
Adware:adware/spywarequake Not disinfected C:\WINDOWS\SYSTEM32\stickrep.dll
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\ms1.exe
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.atwola.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[ad.sensismediasmart.com.au/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.cdfreaks.com/]
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.club.cdfreaks.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Match Not disinfected C:\Documents and Settings\Bonnie\Application Data\Mozilla\Firefox\Profiles\d3n21s3l.default\cookies.txt[promo.match.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Bonnie\Application
Cont'd...