Vcodec and Spy Falcon, they just won't die.

I may have it under control.

I checked the files that the kapersky scan showed, fed them though viruscan and virustotal and they all had trojans in them.

Funilly, Spyware Quake, like Spy Falcon, tried to mask itself as a legit anti spyware program, and because of that, in its window it showed a list of 'infected' files and reg keys.

However, the infected files and reg keys matched what kapersky mentioned as well as confirming some odd registry things I noted a few days ago while reasearching this issue.

So I first downloaded Killbox.

Then went to safe mode, ran smit and S&D then went into H:/Windows/system32 and used killbox to nail dfrgsrv.exe.

Between S&D and smitrem, nvctrl.exe and mssearnet.exe were already gone.

Also uninstalled Spyware Quake.

On a restart I noticed that killbox nailed all the files I asked it too, but Quake still opened.

I went into regedit and deleted the reg keys that quake istelf gave out (they all matched bad reg edits that other solutions I've seen mentioned, as well as having descriptions refering to spy falcon, vcodec, spyware quake, nvctrl, mssearchnet and dfrgsrv. I deleted them all.

Also uninstalled netscape and deleted them temp files, as it was via netscape that my brother got vcodec.

Also used killbox to delete the other infected files that kapersky revealed.

Did a restart and Spyware Quake didn't open.

Did a once over with S&D and didn't get anything (this time vcodec didnt come up).


Looks clean right now and nothing else has revealed itself.

Might be good too go.

Hopefully.
 
Ok, you beat me to it then...as I saw these need to be done:
Remove SpywareQuake in Add/Remove programs via the Control panel

Delete infected emails in Thunderbird inbox

Clear your cache in Netscape

Delete these files found infected on the KAV scan

H:\WINDOWS\system32\dfrgsrv.exe

H:\WINDOWS\system32\ldA604.tmp

H:\WINDOWS\system32\mssearchnet.exe

H:\Documents and Settings\Heath\My Documents\122903.exe

Repeat the Smitfraud removal instructions:
http://forums.spybot.info/showthread.php?t=1958


You are actively engaged in an identical thread at Short Media?
http://www.short-media.com/forum/showthread.php?t=43740

It's somewhat unproductive to be having two of us looking at the same thing. You will get different instructions and different tools mixed up. I can't keep up with what you are doing in two threads. What other forums have you posted all this in? And which one are you going stick with because it's waste of our time if you are following instructions elsewhere.

But I'm glad you think you have it resolved. Just please let other forums know so that it's not wasting our time all looking at the same thing.
 
download Silent Runner's to get a log please.

http://www.silentrunners.org/Silent Runners.zip

* Save it to the desktop and unzip it.
* Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
* You will get a prompt asking about performing supplementary searches.
* Click "No" at that prompt.
* You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
* Once you receive the prompt All Done!, open the text file on the desktop, copy that entire log, and paste it here.

*NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
 
CalamityJane said:
You are actively engaged in an identical thread at Short Media?
http://www.short-media.com/forum/showthread.php?t=43740

It's somewhat unproductive to be having two of us looking at the same thing. You will get different instructions and different tools mixed up. I can't keep up with what you are doing in two threads. What other forums have you posted all this in? And which one are you going stick with because it's waste of our time if you are following instructions elsewhere.

But I'm glad you think you have it resolved. Just please let other forums know so that it's not wasting our time all looking at the same thing.

Indeed, and this topic is closed.
 
Back
Top