Yes It's gone
Fixwareout ver 1.003
Last edited 04/26/2006
Post this report in the forums please
Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\iahmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif
…
Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmhai.exe"=-
…
PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is lagitamate
»»»»» Search by size and names…
»»»»» Misc files
»»»»» Checking for older varients covered by the Rem3 tool
»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSRRS.EXE 155,648 2002-08-29
I right click and clicked delete this time it says cannot delete CSRSS: Access is denied make sure the disk is not full or write-protected and that the is not currently in use. Im going to restart, and try again.
I just ran the program Xoftspy and it found 4 objects. One was a browser highjacker, worm, and two data miners. When I earse them they tend to come back. How could I prevent this from coming back? I have zone alarm pro, but I guess it does not seem to prevent viruses.
Run that program again, and let me know what it finds.
It found nothing, it came out clean. I have to make sure I always open zone alarm pro before browsing. Thank You Micah if I have anymore problems I hope you are here. Thanks to you my pc is virus free, and running smoothly again. Thank You