Page 2 of 2 FirstFirst 12
Results 11 to 19 of 19

Thread: Virtumonde infection... and others

  1. #11
    Junior Member
    Join Date
    Apr 2008
    Posts
    16

    Default

    OK, here's the Kaspersky report:

    -------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER REPORT
    Tuesday, April 08, 2008 8:15:04 AM
    Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 7/04/2008
    Kaspersky Anti-Virus database records: 688898
    -------------------------------------------------------------------------------

    Scan Settings:
    Scan using the following antivirus database: extended
    Scan Archives: true
    Scan Mail Bases: true

    Scan Target - My Computer:
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    I:\
    L:\
    X:\
    Y:\

    Scan Statistics:
    Total number of scanned objects: 336038
    Number of viruses found: 17
    Number of infected objects: 52
    Number of suspicious objects: 2
    Duration of the scan process: 03:51:33

    Infected Object Name / Virus Name / Last Action
    C:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
    D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
    D:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
    D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
    D:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
    D:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-04-07_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
    D:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
    D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    D:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    D:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
    D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    D:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
    D:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
    D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\cert8.db Object is locked skipped
    D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\history.dat Object is locked skipped
    D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\key3.db Object is locked skipped
    D:\Documents and Settings\Matt\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\parent.lock Object is locked skipped
    D:\Documents and Settings\Matt\Cookies\index.dat Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Last.fm\Client\lastfmhelper.log Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_001_ Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_002_ Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_003_ Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Application Data\Mozilla\Firefox\Profiles\vupanqvu.default\Cache\_CACHE_MAP_ Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\History\History.IE5\index.dat Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
    D:\Documents and Settings\Matt\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
    D:\Documents and Settings\Matt\NTUSER.DAT Object is locked skipped
    D:\Documents and Settings\Matt\NTUSER.DAT.LOG Object is locked skipped
    D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
    D:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
    D:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
    D:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
    D:\Documents and Settings\PST Files\matthew.pst/Matthew's PST/Inbox/Shopping & Services/Paypal/15 Mar 2003 06:31 from PayPal Business Bulletin:March Business B.html Suspicious: Trojan-Spy.HTML.Fraud.gen skipped
    D:\Documents and Settings\PST Files\matthew.pst Mail MS Mail: suspicious - 1 skipped
    D:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\debug.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\debug.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\error.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\error.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\hips.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\hips.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\ids.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\ids.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\network.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\network.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\system.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\system.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\warning.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\warning.log.idx Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\web.log Object is locked skipped
    D:\Program Files\Kerio\Personal Firewall 4\logs\web.log.idx Object is locked skipped
    D:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped
    D:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped
    D:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped
    D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip ZIP: infected - 3 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\2BF7523C.zip CryptFF: infected - 3 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe/data0007 Infected: Trojan-Clicker.Win32.Agent.gy skipped
    D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe/data0008 Infected: Trojan-Downloader.Win32.Zlob.jl skipped
    D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe NSIS: infected - 2 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe UPX: infected - 2 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\530315A7.exe CryptFF: infected - 2 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/BlackBox.class Infected: Exploit.Java.ByteVerify skipped
    D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/VerifierBug.class Infected: Exploit.Java.ByteVerify skipped
    D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip/Beyond.class Infected: Trojan-Downloader.Java.OpenConnection.aa skipped
    D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip ZIP: infected - 3 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\755F4FA0.zip CryptFF: infected - 3 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\7D525279/BaaaaBaa.class Infected: Exploit.Java.Gimsh.a skipped
    D:\Program Files\Norton AntiVirus\Quarantine\7D525279 ZIP: infected - 1 skipped
    D:\Program Files\Norton AntiVirus\Quarantine\7D525279 CryptFF: infected - 1 skipped
    D:\Program Files\SnadBoy's Revelation v2\Revelation.exe Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    D:\Program Files\SnadBoy's Revelation v2\RevelationHelper.dll Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP512\A0110980.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111039.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mju skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111052.exe Infected: Trojan-Downloader.Win32.Zlob.is skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111053.exe Infected: Trojan-Downloader.Win32.Zlob.iz skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP513\A0111054.exe Infected: Trojan-Downloader.Win32.Small.cqs skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP514\A0111061.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.msm skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP514\A0111062.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mwq skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP516\A0111180.dll Infected: Packed.Win32.Monder skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP516\A0111181.dll Infected: not-a-virus:AdWare.Win32.Virtumonde.mxi skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe/data0000.cab/toolbar.exe Infected: Packed.Win32.Monder skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe/data0000.cab Infected: Packed.Win32.Monder skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP520\A0111954.exe Rsrc-Package: infected - 2 skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe/data0000.cab/toolbar.exe Infected: Packed.Win32.Monder skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe/data0000.cab Infected: Packed.Win32.Monder skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\A0113324.exe Rsrc-Package: infected - 2 skipped
    D:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
    D:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
    D:\WINDOWS\SchedLgU.Txt Object is locked skipped
    D:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
    D:\WINDOWS\Sti_Trace.log Object is locked skipped
    D:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
    D:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
    D:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
    D:\WINDOWS\system32\config\default Object is locked skipped
    D:\WINDOWS\system32\config\default.LOG Object is locked skipped
    D:\WINDOWS\system32\config\Internet.evt Object is locked skipped
    D:\WINDOWS\system32\config\SAM Object is locked skipped
    D:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
    D:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
    D:\WINDOWS\system32\config\SECURITY Object is locked skipped
    D:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
    D:\WINDOWS\system32\config\software Object is locked skipped
    D:\WINDOWS\system32\config\software.LOG Object is locked skipped
    D:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
    D:\WINDOWS\system32\config\system Object is locked skipped
    D:\WINDOWS\system32\config\system.LOG Object is locked skipped
    D:\WINDOWS\system32\drivers\atapi.sys Object is locked skipped
    D:\WINDOWS\system32\h323log.txt Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
    D:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
    D:\WINDOWS\wiadebug.log Object is locked skipped
    D:\WINDOWS\wiaservc.log Object is locked skipped
    D:\WINDOWS\WindowsUpdate.log Object is locked skipped
    D:\_DVD\Software\Internet\mirc616.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
    D:\_DVD\Software\Internet\mirc616.exe mIRC: infected - 1 skipped
    D:\_DVD\Software\Internet\mirc62.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    D:\_DVD\Software\Internet\mirc62.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    D:\_DVD\Software\Internet\mirc62.exe NSIS: infected - 2 skipped
    D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    D:\_DVD\Software\Windows Utils\SetupRevelationV2.exe WiseSFX: infected - 2 skipped
    E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe/WISE0012.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe/WISE0013.BIN Infected: not-a-virus:PSWTool.Win32.SnadBoy.2011 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108095.exe WiseSFX: infected - 2 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108158.exe/data0001.bin Infected: not-a-virus:Client-IRC.Win32.mIRC.616 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108158.exe mIRC: infected - 1 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe/stream/data0006 Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.62 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP499\A0108159.exe NSIS: infected - 2 skipped
    E:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped
    F:\System Volume Information\_restore{791D385F-71B2-4149-918D-BD79E9BFA7FD}\RP522\change.log Object is locked skipped

    Scan process completed.

  2. #12
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Hello

    1. Close any open browsers.

    2. Open notepad and copy/paste the text in the quotebox below into it:

    File::
    D:\WINDOWS\system32\aefbdspl.ini
    D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q

    Folder::
    D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q
    Save this as CFScript.txt, in the same location as ComboFix.exe




    Refering to the picture above, drag CFScript into ComboFix.exe

    When finished, it shall produce a log for you at "C:\ComboFix.txt"

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall




    Also tell me how your PC is running
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  3. #13
    Junior Member
    Join Date
    Apr 2008
    Posts
    16

    Default

    Hi, this didn't work. The ComboFix cmd window popped up briefly, no messages appeared, then it closed again. No new report has been generated.

  4. #14
    Junior Member
    Join Date
    Apr 2008
    Posts
    16

    Default

    Aslso, other than this problem with ComboFix, my PC is running fine at the moment. No code injection warnings and all the weird stuff I was having before has stopped. I'm aware I still need to run a virus check to remove those listed by Kaspersky in my report above, but I thought I'd best wait for your instructions regarding that.

  5. #15
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Do this instead

    Please download the OTMoveIt2 by OldTimer.
    • Save it to your desktop.
    • Please double-click OTMoveIt2.exe to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code:
      [kill explorer]
      D:\WINDOWS\system32\aefbdspl.ini
      D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q
      purity 
      [start explorer]
    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
    • Close OTMoveIt2
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


    Reboot and tell me how your PC is running
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  6. #16
    Junior Member
    Join Date
    Apr 2008
    Posts
    16

    Default

    Hi, thank you for the update. Here's the log from OTMoveit2. The PC seems to be running very well.



    Explorer killed successfully
    D:\WINDOWS\system32\aefbdspl.ini moved successfully.
    D:\Documents and Settings\All Users\Application Data\SecTaskMan\lrgljqkp.dll.q_805D040_q moved successfully.
    < purity >
    Explorer started successfully

    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04082008_191347

  7. #17
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Your logs are clean ! We need to do a few things

    Follow these steps to uninstall Combofix and tools used in the removal of malware
    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.



    • Make sure you have an Internet Connection.
    • Double-click OTMoveIt2.exe to run it.
    • Click on the CleanUp! button
    • A list of tool components used in the Cleanup of malware will be downloaded.
    • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
    • Click Yes to beging the Cleanup process and remove these components, including this application.
    • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.



    You now need to update your Java and remove your older versions.

    Please follow these steps to remove older version Java components.

    * Click Start > Control Panel.
    * Click Add/Remove Programs.
    * Check any item with Java Runtime Environment (JRE) in the name.
    * Click the Remove or Change/Remove button.

    Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
    here



    Below I have included a number of recommendations for how to protect your computer against malware infections.

    * Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

    * To reduce re-infection for malware in the future, I strongly recommend installing these free programs:
    SpywareBlaster protects against bad ActiveX
    IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
    Have a look at this tutorial for IE-Spyad here

    * SpywareGuard offers realtime protection from spyware installation attempts.

    Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.


    * MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

    * Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here

    * Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
    Here

    Thank you for your patience, and performing all of the procedures requested.
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

  8. #18
    Junior Member
    Join Date
    Apr 2008
    Posts
    16

    Default

    Excellent! Thank you very much for all your help! Now, I am going to get rid of Norton (it didn't find the source of the infection) and buy a better anti-virus!

    I owe you a guinness or two!

  9. #19
    Retired Security Volunteer
    Join Date
    Sep 2007
    Location
    Ireland
    Posts
    1,620

    Default

    Sounds like a plan

    Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

    Note: If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

    If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
    Who watches The Watchmen?

    It's like you said. All I am is what I'm going after.

    ~Scratch~

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •