This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

hey there

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there tom coyote, i got this annoying aurora adware thingie, amongst others, y'all helped me out before, can you do it again?
Heres my Hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 2:19:01 AM, on 7/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
C:\program files\aim\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\windows\system32\pznycym.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pharm-text.com/pharmaecopia/index.php?

sid=84cb8b520b2db4b5bca1b6ee42fab7b0
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0

\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0

\gnotify.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [owjsya] c:\windows\system32\pznycym.exe
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\program files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Kel\LOCALS~1\Temp\Rar$EX00.703\HijackThis.exe /startupscan
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\program files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
Click here to download ewido security suite - it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed. If you are having problems with the updater, you can use this link to manually update ewido. Do NOT run a scan yet.

Click here to download Nailfix. Unzip it to the desktop but please do NOT run it yet.

When you have the applicactions, reboot into Safe Mode by tapping F8 after the BIOS has loaded. Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly - this is normal.

Next open ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin (do not open any folders or open the windows control panel while the scan is in progress).
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.

Open HijackThis, scan and when complete, remove the following entries if still there by checking the box to the left and clicking 'fixed checked':

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [owjsya] c:\windows\system32\pznycym.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

Find and delete the following:

C:\WINDOWS\wupdt.exe
c:\windows\system32\pznycym.exe

Reboot into Normal Mode when done, rescan with HJT and post a new log here together with the ewido report you saved.
Heres my HJT log
ckThis v1.99.1
Scan saved at 12:59:04 AM, on 7/24/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
C:\program files\aim\aim.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijackthis\HijackThis.exe
c:\windows\system32\ikqpixj.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://pharm-text.com/pharmaecopia/index.p…ca1b6ee42fab7b0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\G001-1.0.24.0\gnotify.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [gskweny] c:\windows\system32\ikqpixj.exe r
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [AIM] C:\program files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [HijackThis startup scan] C:\DOCUME~1\Kel\LOCALS~1\Temp\Rar$EX00.703\HijackThis.exe /startupscan
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\program files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE

Heres my ewido logfile

——————————————
ewido security suite - Scan report
———————————————————

+ Created on: 12:49:13 AM, 7/24/2005
+ Report-Checksum: 494FEBF4

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000010-6F7D-442C-93E3-4A4827C2E4C8} -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{10E42047-DEB9-4535-A118-B3F6EC39B807} -> Spyware.SideFind : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{86227D9C-0EFE-4F8A-AA55-30386A3F5686} -> Spyware.YourSiteBar : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A3FDD654-A057-4971-9844-4ED8E67DBBB8} -> Spyware.ISTBar : Cleaned with backup
HKU\S-1-5-21-1546884879-2866516396-85267409-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F4E04583-354E-4076-BE7D-ED6A80FD66DA} -> Spyware.BargainBuddy : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@112.2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@clickagents[2].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@targetnet[2].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\kel@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][1].txt -> Spyware.Cookie.Directnetadvertising : Cleaned with backup
C:\Documents and Settings\Kel\Cookies\[removed][2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temp\BTU\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temp\fFGFHQp.exe -> TrojanDownloader.IstBar.ir : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temp\iinstall.exe -> TrojanDownloader.IstBar : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temp\NFC\polupg.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temp\THI5EB8.tmp\farmmext.cab/farmmext.exe -> Spyware.ConsCorr : Cleaned with backup
C:\Documents and Settings\Kel\Local Settings\Temporary Internet Files\Content.IE5\07QXMHIP\Poller[1].exe -> Trojan.Agent.cp : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\8449ED0D-906E-41A5-87CB-39A496\100BEF0C-0EF7-4BAB-A934-8D7AE8 -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\BE1AC330-0852-4853-B171-000A5C\FE51A64F-2EEE-4E2C-968A-E7DBFF -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\01d6nvg468.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\1xk8nn6dg5.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\1yf6wen65j.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\4xpr0xuk3u.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\57opstyv5d.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\7f9n8d78bh.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\7w3wd84gjw.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\8rd3ka3599.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\8ztc00iiv8.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\911wxmlg9x.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\9robsh0z57.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\a3m03fco8j.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\azjangwzd8.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\b9wzxfar42.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\bcdd30sg9o.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\bd2reopmsh.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\byztehah78.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\c0jnylnyxl.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\cspkfn3aho.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\ctjvmzlvt3.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\cvyt6s7j77.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\eoe22norfc.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\fskhgetnyz.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\g8piylitxf.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\ikvv9raa5k.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\iu98f7ic9h.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\jdcnr213v4.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\jzrvkygrus.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\kh9jzpt235.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\klc5nnzanf.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\kmkdjbvnabr.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\n59673zhsk.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\olccl5wskn.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\pxga33kxa8.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\r61erxrdrp.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar : Cleaned with backup
C:\WINDOWS\system32\1054750.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\1229046.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\13608593.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\13789671.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\14142156.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\14754312.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\150546.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\15174421.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\152906.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\15716921.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\15898875.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\16021828.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\16262781.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\16565421.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\16748562.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\16928937.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\29296.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\2971468.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\2971765.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\328343.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\3336265.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\3587343.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\3812281.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\4001265.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\4122343.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\42905234.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\42914031.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\4366875.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\452062.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\510109.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\51655796.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\51837546.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\53280750.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\630750.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\634546.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\777390.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\870781.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\89593.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\931015.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\9327703.exe -> Trojan.Regger.d : Cleaned with backup
C:\WINDOWS\system32\idgpry.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\tx0o759pr4.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\uavm8xs447.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\ujml7py1pt.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\wbc5gsei4p.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c : Cleaned with backup
C:\WINDOWS\yupch4xva2.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\yushc36v7z.exe -> TrojanDropper.Small.ju : Cleaned with backup
C:\WINDOWS\zona01.exe -> Trojan.Dissec.a : Cleaned with backup


::Report End
OK, you've still got an awkward little trojan in there. Please post a new HJT log and don't reboot/switch off from now on unless instructed to do so.
Due to inactivity this topic will be closed. If you need this topic reopened, please email the moderating team - be sure to include the address of the thread and the name you posted under.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI