spware / malware / ...: sitebar and other files

Discussion in 'Malware Help (A Specialist Will Reply)' started by da_foz, Oct 23, 2005.

  1. da_foz

    da_foz Private E-2

    I found this formum while trying to get rid of some crap on my computer. I'm not totally sure what I have but there is something here that won't go away. I have gone through the 'do me first' thing (http://forums.majorgeeks.com/showthread.php?t=35407) and found a bunch of things. I cleaned them all out but (almost) all of them have returned so I'm guessing I have a bigger problem that I need to find first.

    I had been looking at this thread (http://forums.majorgeeks.com/showthread.php?p=663469#post663469) as it seemed like it might be close to what I have but no go.

    Windows 2000, all updates have been done.

    Here is a screen shot of what pops up when a network connect is made. You have also see some files on my c:\ drive.
    http://www.redclaw.ca/images/help.jpg
    After I close the sitebar window (using the 'x' in the top right corner) if I don't close the command prompt fast enough it opens IE and tries to get me to install other things.
    I have deleted the following files a number of times but they keep coming back:
    is.exe
    low.exe
    mmxateam.exe
    tb.exe
    ex.exe
    zxvcc73x.exe

    Ad-aware also finds the following entries which I clean but they alway return:

    Vendor Type Object

    DyFuCA Regkey Malware HKEY_USERS:.DEFAULT\software\ist
    DyFuCA RegValue Malware HKEY_USERS:.DEFAULT\software\ist\exe_start

    Here is a hijackthis log:
    http://www.redclaw.ca/images/hijackthis.log

    I have run all of the online scans and I have done / cleaned everything they found. I don't know what else to do.

    If anyone has any ideas please let me know, also please post if there is any other information that may be of use.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow guidelines per step 7 of the READ ME sticky thread for installing, running and posting HJT logs properly here on MGs as an attachment to your message. I would also recommend that you run the below before posting a new HJT log and also post the log from Ewido (as an attachment).

    Running Ewido Security Suite
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds