Need Help with spyware removal

Discussion in 'Malware Help (A Specialist Will Reply)' started by jahanzed, Aug 5, 2006.

  1. jahanzed

    jahanzed Private E-2

    Attached Files:

  2. jahanzed

    jahanzed Private E-2

    this is BDSCAN.HTML

    coz i cant attach it ...its an html file...so im just pasting it




    BitDefender Online Scanner







    Scan report generated at: Sat, Aug 05, 2006 - 12:19:45









    Scan path: C:\;D:\;















    Statistics

    Time


    01:23:18

    Files


    435157

    Folders


    3503

    Boot Sectors


    2

    Archives


    7390

    Packed Files


    58835







    Results

    Identified Viruses


    1

    Infected Files


    1

    Suspect Files


    0

    Warnings


    0

    Disinfected


    0

    Deleted Files


    0







    Engines Info

    Virus Definitions


    426902

    Engine build


    AVCORE v1.0 (build 2310) (i386) (Apr 17 2006 16:24:38)

    Scan plugins


    13

    Archive plugins


    39

    Unpack plugins


    5

    E-mail plugins


    6

    System plugins


    1







    Scan Settings

    First Action


    Disinfect

    Second Action


    Delete

    Heuristics


    Yes

    Enable Warnings


    Yes

    Scanned Extensions


    *;

    Exclude Extensions




    Scan Emails


    Yes

    Scan Archives


    Yes

    Scan Packed


    Yes

    Scan Files


    Yes

    Scan Boot


    Yes








    Scanned File


    Status

    C:\WINDOWS\cfdemo.exe


    Clean

    C:\WINDOWS\cfdemo.scr


    Clean

    C:\WINDOWS\clock.avi


    Clean

    C:\WINDOWS\Coffee Bean.bmp


    Clean

    C:\WINDOWS\control.ini


    Clean

    C:\WINDOWS\Cursors\3dgarro.cur


    Clean

    C:\WINDOWS\Cursors\3dgmove.cur


    Clean

    C:\WINDOWS\Cursors\3dgnesw.cur


    Clean

    C:\WINDOWS\Cursors\3dgno.cur


    Clean

    C:\WINDOWS\Cursors\3dgns.cur


    Clean

    C:\WINDOWS\Cursors\3dgnwse.cur


    Clean

    C:\WINDOWS\Cursors\3dgwe.cur


    Clean

    C:\WINDOWS\Cursors\3dsmove.cur


    Clean

    C:\WINDOWS\Cursors\3dsns.cur


    Clean

    C:\WINDOWS\Cursors\3dsnwse.cur


    Clean

    C:\WINDOWS\Cursors\3dwarro.cur


    Clean

    C:\WINDOWS\Cursors\3dwmove.cur


    Clean

    C:\WINDOWS\Cursors\3dwnesw.cur


    Clean

    C:\WINDOWS\Cursors\3dwno.cur


    Clean

    C:\WINDOWS\Cursors\3dwns.cur


    Clean

    C:\WINDOWS\Cursors\3dwnwse.cur


    Clean

    C:\WINDOWS\Cursors\3dwwe.cur


    Clean

    C:\WINDOWS\Cursors\appstar2.ani


    Clean

    C:\WINDOWS\Cursors\appstar3.ani


    Clean

    C:\WINDOWS\Cursors\appstart.ani


    Clean

    C:\WINDOWS\Cursors\arrow_i.cur


    Clean

    C:\WINDOWS\Cursors\arrow_il.cur


    Clean

    C:\WINDOWS\Cursors\arrow_im.cur


    Clean

    C:\WINDOWS\Cursors\arrow_l.cur


    Clean

    C:\WINDOWS\Cursors\arrow_m.cur


    Clean

    C:\WINDOWS\Cursors\arrow_r.cur


    Clean

    C:\WINDOWS\Cursors\arrow_rl.cur


    Clean

    C:\WINDOWS\Cursors\arrow_rm.cur


    Clean

    C:\WINDOWS\Cursors\banana.ani


    Clean

    C:\WINDOWS\Cursors\barber.ani


    Clean

    C:\WINDOWS\Cursors\beam_i.cur


    Clean

    C:\WINDOWS\Cursors\beam_il.cur


    Clean

    C:\WINDOWS\Cursors\beam_im.cur


    Clean

    C:\WINDOWS\Cursors\beam_l.cur


    Clean

    C:\WINDOWS\Cursors\beam_m.cur


    Clean

    C:\WINDOWS\Cursors\beam_r.cur


    Clean

    C:\WINDOWS\Cursors\beam_rl.cur


    Clean

    C:\WINDOWS\Cursors\beam_rm.cur


    Clean

    C:\WINDOWS\Cursors\busy_i.cur


    Clean

    C:\WINDOWS\Cursors\busy_il.cur


    Clean

    C:\WINDOWS\Cursors\busy_im.cur


    Clean

    C:\WINDOWS\Cursors\busy_l.cur


    Clean

    C:\WINDOWS\Cursors\busy_m.cur


    Clean

    C:\WINDOWS\Cursors\busy_r.cur


    Clean

    C:\WINDOWS\Cursors\busy_rl.cur


    Clean

    C:\WINDOWS\Cursors\busy_rm.cur


    Clean

    C:\WINDOWS\Cursors\coin.ani


    Clean

    C:\WINDOWS\Cursors\counter.ani


    Clean

    C:\WINDOWS\Cursors\cross.cur


    Clean

    C:\WINDOWS\Cursors\cross_i.cur


    Clean

    C:\WINDOWS\Cursors\cross_il.cur


    Clean

    C:\WINDOWS\Cursors\cross_im.cur


    Clean

    C:\WINDOWS\Cursors\cross_l.cur


    Clean

    C:\WINDOWS\Cursors\cross_m.cur


    Clean

    C:\WINDOWS\Cursors\cross_r.cur


    Clean

    C:\WINDOWS\Cursors\cross_rl.cur


    Clean

    C:\WINDOWS\Cursors\cross_rm.cur


    Clean

    C:\WINDOWS\Cursors\dinosau2.ani


    Clean

    C:\WINDOWS\Cursors\dinosaur.ani


    Clean

    C:\WINDOWS\Cursors\drum.ani


    Clean

    C:\WINDOWS\Cursors\fillitup.ani


    Clean

    C:\WINDOWS\Cursors\hand.ani


    Clean

    C:\WINDOWS\Cursors\handapst.ani


    Clean

    C:\WINDOWS\Cursors\handnesw.ani


    Clean

    C:\WINDOWS\Cursors\handno.ani


    Clean

    C:\WINDOWS\Cursors\handns.ani


    Clean

    C:\WINDOWS\Cursors\handnwse.ani


    Clean

    C:\WINDOWS\Cursors\handwait.ani


    Clean

    C:\WINDOWS\Cursors\handwe.ani


    Clean

    C:\WINDOWS\Cursors\harrow.cur


    Clean

    C:\WINDOWS\Cursors\hcross.cur


    Clean

    C:\WINDOWS\Cursors\help_i.cur


    Clean

    C:\WINDOWS\Cursors\help_il.cur


    Clean

    C:\WINDOWS\Cursors\help_im.cur


    Clean

    C:\WINDOWS\Cursors\help_l.cur


    Clean

    C:\WINDOWS\Cursors\help_m.cur


    Clean

    C:\WINDOWS\Cursors\help_r.cur


    Clean

    C:\WINDOWS\Cursors\help_rl.cur


    Clean

    C:\WINDOWS\Cursors\help_rm.cur


    Clean

    C:\WINDOWS\Cursors\hibeam.cur


    Clean

    C:\WINDOWS\Cursors\hmove.cur


    Clean

    C:\WINDOWS\Cursors\hnesw.cur


    Clean

    C:\WINDOWS\Cursors\hnodrop.cur


    Clean

    C:\WINDOWS\Cursors\hns.cur


    Clean

    C:\WINDOWS\Cursors\hnwse.cur


    Clean

    C:\WINDOWS\Cursors\horse.ani


    Clean

    C:\WINDOWS\Cursors\hourgla2.ani


    Clean

    C:\WINDOWS\Cursors\hourgla3.ani


    Clean

    C:\WINDOWS\Cursors\hourglas.ani


    Clean

    C:\WINDOWS\Cursors\hwe.cur


    Clean

    C:\WINDOWS\Cursors\lappstrt.cur


    Clean

    C:\WINDOWS\Cursors\larrow.cur


    Clean

    C:\WINDOWS\Cursors\lcross.cur


    Clean

    C:\WINDOWS\Cursors\libeam.cur


    Clean

    C:\WINDOWS\Cursors\lmove.cur


    Clean

    C:\WINDOWS\Cursors\lnesw.cur


    Clean

    C:\WINDOWS\Cursors\lnodrop.cur


    Clean

    C:\WINDOWS\Cursors\lns.cur


    Clean

    C:\WINDOWS\Cursors\lnwse.cur


    Clean

    C:\WINDOWS\Cursors\lwait.cur


    Clean

    C:\WINDOWS\Cursors\lwe.cur


    Clean

    C:\WINDOWS\Cursors\metronom.ani


    Clean

    C:\WINDOWS\Cursors\move_i.cur


    Clean

    C:\WINDOWS\Cursors\move_il.cur


    Clean

    C:\WINDOWS\Cursors\move_im.cur


    Clean

    C:\WINDOWS\Cursors\move_l.cur


    Clean

    C:\WINDOWS\Cursors\move_m.cur


    Clean

    C:\WINDOWS\Cursors\move_r.cur


    Clean

    C:\WINDOWS\Cursors\move_rl.cur


    Clean

    C:\WINDOWS\Cursors\move_rm.cur


    Clean

    C:\WINDOWS\Cursors\no_i.cur


    Clean

    C:\WINDOWS\Cursors\no_il.cur


    Clean

    C:\WINDOWS\Cursors\no_im.cur


    Clean

    C:\WINDOWS\Cursors\no_l.cur


    Clean

    C:\WINDOWS\Cursors\no_m.cur


    Clean

    C:\WINDOWS\Cursors\no_r.cur


    Clean

    C:\WINDOWS\Cursors\no_rl.cur


    Clean

    C:\WINDOWS\Cursors\no_rm.cur


    Clean

    C:\WINDOWS\Cursors\pen_i.cur


    Clean

    C:\WINDOWS\Cursors\pen_il.cur


    Clean

    C:\WINDOWS\Cursors\pen_im.cur


    Clean

    C:\WINDOWS\Cursors\pen_l.cur


    Clean

    C:\WINDOWS\Cursors\pen_m.cur


    Clean

    C:\WINDOWS\Cursors\pen_r.cur


    Clean

    C:\WINDOWS\Cursors\pen_rl.cur


    Clean

    C:\WINDOWS\Cursors\pen_rm.cur


    Clean

    C:\WINDOWS\Cursors\piano.ani


    Clean

    C:\WINDOWS\Cursors\rainbow.ani


    Clean

    C:\WINDOWS\Cursors\raindrop.ani


    Clean

    C:\WINDOWS\Cursors\size1_i.cur


    Clean

    C:\WINDOWS\Cursors\size1_il.cur


    Clean

    C:\WINDOWS\Cursors\size1_im.cur


    Clean

    C:\WINDOWS\Cursors\size1_l.cur


    Clean

    C:\WINDOWS\Cursors\size1_m.cur


    Clean

    C:\WINDOWS\Cursors\size1_r.cur


    Clean

    C:\WINDOWS\Cursors\size1_rl.cur


    Clean

    C:\WINDOWS\Cursors\size1_rm.cur


    Clean

    C:\WINDOWS\Cursors\size2_i.cur


    Clean

    C:\WINDOWS\Cursors\size2_il.cur


    Clean

    C:\WINDOWS\Cursors\size2_im.cur


    Clean

    C:\WINDOWS\Cursors\size2_l.cur


    Clean

    C:\WINDOWS\Cursors\size2_m.cur


    Clean

    C:\WINDOWS\Cursors\size2_r.cur


    Clean

    C:\WINDOWS\Cursors\size2_rl.cur


    Clean

    C:\WINDOWS\Cursors\size2_rm.cur


    Clean

    C:\WINDOWS\Cursors\size3_i.cur


    Clean

    C:\WINDOWS\Cursors\size3_il.cur


    Clean

    C:\WINDOWS\Cursors\size3_im.cur


    Clean

    C:\WINDOWS\Cursors\size3_l.cur


    Clean

    C:\WINDOWS\Cursors\size3_m.cur


    Clean

    C:\WINDOWS\Cursors\size3_r.cur


    Clean

    C:\WINDOWS\Cursors\size3_rl.cur


    Clean

    C:\WINDOWS\Cursors\size3_rm.cur


    Clean

    C:\WINDOWS\Cursors\size4_i.cur


    Clean

    C:\WINDOWS\Cursors\size4_il.cur


    Clean

    C:\WINDOWS\Cursors\size4_im.cur


    Clean

    C:\WINDOWS\Cursors\size4_l.cur


    Clean

    C:\WINDOWS\Cursors\size4_m.cur


    Clean

    C:\WINDOWS\Cursors\size4_r.cur


    Clean

    C:\WINDOWS\Cursors\size4_rl.cur


    Clean

    C:\WINDOWS\Cursors\size4_rm.cur


    Clean

    C:\WINDOWS\Cursors\sizenesw.ani


    Clean

    C:\WINDOWS\Cursors\sizens.ani


    Clean

    C:\WINDOWS\Cursors\sizenwse.ani


    Clean

    C:\WINDOWS\Cursors\sizewe.ani


    Clean

    C:\WINDOWS\Cursors\stopwtch.ani


    Clean

    C:\WINDOWS\Cursors\up_i.cur


    Clean

    C:\WINDOWS\Cursors\up_il.cur


    Clean

    C:\WINDOWS\Cursors\up_im.cur


    Clean

    C:\WINDOWS\Cursors\up_l.cur


    Clean

    C:\WINDOWS\Cursors\up_m.cur


    Clean

    C:\WINDOWS\Cursors\up_r.cur


    Clean

    C:\WINDOWS\Cursors\up_rl.cur


    Clean

    C:\WINDOWS\Cursors\up_rm.cur


    Clean

    C:\WINDOWS\Cursors\vanisher.ani


    Clean

    C:\WINDOWS\Cursors\wagtail.ani


    Clean

    C:\WINDOWS\Cursors\wait_i.cur


    Clean

    C:\WINDOWS\Cursors\wait_il.cur


    Clean

    C:\WINDOWS\Cursors\wait_im.cur


    Clean

    C:\WINDOWS\Cursors\wait_l.cur


    Clean

    C:\WINDOWS\Cursors\wait_m.cur


    Clean

    C:\WINDOWS\Cursors\wait_r.cur


    Clean

    C:\WINDOWS\Cursors\wait_rl.cur


    Clean

    C:\WINDOWS\Cursors\wait_rm.cur


    Clean

    C:\WINDOWS\Debug\mrt.log


    Clean

    C:\WINDOWS\Debug\mrt.log=>(unicode)


    Clean

    C:\WINDOWS\Debug\mrt.log.old


    Clean

    C:\WINDOWS\Debug\PASSWD.LOG


    Clean

    C:\WINDOWS\Debug\WPD\wpdtrace.log


    Clean

    C:\WINDOWS\desktop.ini


    Clean

    C:\WINDOWS\Downloaded Installations\{78CB0701-6520-4FAE-99CE-20DE50BEF25C}\Microsoft AntiSpyware.msi


    Clean

    C:\WINDOWS\system32\inetl32.dll


    Infected with: Trojan.Downloader.Conhook.P

    C:\WINDOWS\system32\inetl32.dll


    Disinfection failed

    C:\WINDOWS\system32\inetl32.dll


    Delete failed



    ------------------------


    I ran BDSCAN before panda scan.
     

    Attached Files:

  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click Delete Selected Temp Files

    Then after it deletes the files click the Exit (Save Settings) button.

    NOTE: Pocket Killbox will only list the added files it is able to find on the system. So when you do the below, if some files do not show in the list after pasting them in, just continue..

    Select:
    • Delete on Reboot
    • then Click on the All Files button.
    • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):
    • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
    • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open ExplorerXP navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Post a fresh HijackThis log.
     
  4. jahanzed

    jahanzed Private E-2

    here is a fresh HJT log..
    thanks for ur help.
     

    Attached Files:

  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Run HijackThis. Click the 'Do a system scan only' button. Place a checkmark in the box next to the following lines:
    Click on the 'Fix checked' button. Wait for HijackThis to finish; close HijackThis.

    Reboot

    Post a fresh HijackThis log.
     
  6. jahanzed

    jahanzed Private E-2

    here is a fresh HJT log file
     

    Attached Files:

  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your HijackThis log is clean.

    How is your computer running?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds