My computor has been taken over by the stealthSWs114.h!dll trojan. I have read and followed a previous post to the same problem with no results. I ran the ewido, Panda Active scanSmitRem and Ad-Aware.
Here are the files:
ewido anti-malware - Startup report
---------------------------------------------------------
Spyware:Cookie/Spyfalcon Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[www.spyfalcon.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[server.iad.liveperson.net/hc/90594700]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.overture.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.landing.domainsponsor.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.go.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/hc/22023924]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/hc/1272494]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.atdmt.com/]
Panda report:
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statse.webtrendslive.com/dcsedqnxhwievvjcfrrxpnm9d_1j7j]
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.data.coremetrics.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@com[1].txt
Adware:Adware/Trymedia Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\Jasons folder\DinerDashSetup-dm.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\smitRem.exe[smitRem/Process.exe]
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Possible Virus. Not disinfected C:\Program Files\Anonymizer\tss\tsslite.exe
Possible Virus. Not disinfected C:\Program Files\Common Files\Wise Installation Wizard\WISEB8D9C06E10741DC8925125FF1C413D5_1_4_1.MSI[unk_0021][tss.exe]
Spyware:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.0
Ad-aware
ArchiveData(auto-quarantine- 2006-05-01 02-53-41.bckp)
Referencefile : SE1R105 26.04.2006
======================================================
NAVEXCEL
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : interface\{4d6ced50-d6ae-40da-b87f-235593fc1f28}
obj[1]=RegValue : software\microsoft\internet explorer\toolbar "{5AA06644-BC46-4220-A460-47A6EB47C96D}"
obj[2]=Folder : C:\Program Files\NavExcel
obj[3]=Folder : C:\Program Files\navexcel\NavHelper
COULOMB DIALER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[6]=File : C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Shockwave Player\xtras\download\TheGrooveAlliance\3DGrooveXtrav181\Groove.x32
obj[7]=File : C:\Program Files\Online Services\PeoplePC\Utilities\AtlBrowser.exe
WINFIXER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[8]=File : C:\System Volume Information\_restore{55AD45FB-8993-4F27-867B-0B74F04FFF84}\RP411\A0050052.dll
Any suggestions?
Here are the files:
ewido anti-malware - Startup report
---------------------------------------------------------
Spyware:Cookie/Spyfalcon Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[www.spyfalcon.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[server.iad.liveperson.net/hc/90594700]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.overture.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.landing.domainsponsor.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.go.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/hc/22023924]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.server.iad.liveperson.net/hc/1272494]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.atdmt.com/]
Panda report:
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.statse.webtrendslive.com/dcsedqnxhwievvjcfrrxpnm9d_1j7j]
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.data.coremetrics.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.belnk.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Compaq_Owner\Application Data\Netscape\NSB\Profiles\mmtrvup2.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Compaq_Owner\Cookies\compaq_owner@com[1].txt
Adware:Adware/Trymedia Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\Jasons folder\DinerDashSetup-dm.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Owner\Desktop\smitRem.exe[smitRem/Process.exe]
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Possible Virus. Not disinfected C:\Program Files\Anonymizer\tss\tsslite.exe
Possible Virus. Not disinfected C:\Program Files\Common Files\Wise Installation Wizard\WISEB8D9C06E10741DC8925125FF1C413D5_1_4_1.MSI[unk_0021][tss.exe]
Spyware:application/bestoffer Not disinfected C:\WINDOWS\smdat32m.sys
Virus:Trj/Qhost.gen Disinfected C:\WINDOWS\system32\drivers\etc\hosts.0
Ad-aware
ArchiveData(auto-quarantine- 2006-05-01 02-53-41.bckp)
Referencefile : SE1R105 26.04.2006
======================================================
NAVEXCEL
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Regkey : interface\{4d6ced50-d6ae-40da-b87f-235593fc1f28}
obj[1]=RegValue : software\microsoft\internet explorer\toolbar "{5AA06644-BC46-4220-A460-47A6EB47C96D}"
obj[2]=Folder : C:\Program Files\NavExcel
obj[3]=Folder : C:\Program Files\navexcel\NavHelper
COULOMB DIALER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[6]=File : C:\Documents and Settings\Compaq_Owner\Application Data\Macromedia\Shockwave Player\xtras\download\TheGrooveAlliance\3DGrooveXtrav181\Groove.x32
obj[7]=File : C:\Program Files\Online Services\PeoplePC\Utilities\AtlBrowser.exe
WINFIXER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[8]=File : C:\System Volume Information\_restore{55AD45FB-8993-4F27-867B-0B74F04FFF84}\RP411\A0050052.dll
Any suggestions?