I have been having problems eliminating purityscan. Here is my logs from hijack this and ewido.
Logfile of HijackThis v1.99.1
Scan saved at 7:50:34 PM, on 9/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
HKU\.DEFAULT\Software\intexp -> Adware.IEPlugin : No action taken.
HKU\.DEFAULT\Software\intexp\Config -> Adware.IEPlugin : No action taken.
HKU\.DEFAULT\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : No action taken.
HKU\S-1-5-18\Software\intexp -> Adware.IEPlugin : No action taken.
HKU\S-1-5-18\Software\intexp\Config -> Adware.IEPlugin : No action taken.
HKU\S-1-5-18\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : No action taken.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A1A109F-58B3-414B-9829-5F4D9BE5FEDE} -> Adware.Virtumonde : No action taken.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7A1A109F-58B3-414B-9829-5F4D9BE5FEDE} -> Adware.Virtumonde : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Leigh\Cookies\leigh@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@abetterinternet[2].txt -> TrackingCookie.Abetterinternet : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Leigh\Cookies\leigh@cliks[2].txt -> TrackingCookie.Cliks : No action taken.
C:\Documents and Settings\Michael\Cookies\michael@cliks[2].txt -> TrackingCookie.Cliks : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][1].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Leigh\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Grays\Cookies\grays@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
I'm Gary R. I'll be glad to help you with your computer problems.
Please be patient, I know that you want your problems solved quickly, and I will work hard to help you.
Please observe these rules while we work:
Perform all actions in the order given.
If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Stick with it till you're given the all clear.
Remember, absence of symptoms does not mean the infection is all gone.
If you can do these things, everything should go smoothly.
I don't see any signs of Purity Scan in your HJT log, however there are things to attend to. You ran Ewido as a scan only, therefore it has not attempted to remove anything it found.
We need to remove a service.
Click Start > Run now type sc stop terms click OK.
Click Start > Run now type sc delete terms click OK.
Note: There is a space between sc and stop/delete, and a space between stop/delete and servicename.
Update Ewido
At the top of the main screen click Update.
Then in the Manual Update section, click on Start Update.
The update will start and a progress bar will show the updates being installed.
When updates are completed, close Ewido.
If you are having problems with the updater, you can use this link to manually update ewido. ewido manual updates
Run a scan with Ewido.
Click on Scanner
Click on the Settings tab, and set the following settings.
How to act
Click on Recommended actions, and set to Quarantine.
How to scan
Check all options.
Possibly unwanted software.
Check all options.
Reports
Check Automatically generate report after every scan.
Uncheck Only if threats were found.
What to scan
Check Scan every file.
Click on the Scan tab.
Click on Complete System Scan and the scan will begin.
When the scan has finished
Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.
Close ewido anti-malware.
Ewido will save a report in the following location C:\Program Files\ewido anti-spyware 4.0\Reports
Please do an online scan withKaspersky Online Scanner
Note: You must be using Internet Explorer as your browser as it will be necessary to install an Active X component to your computer.
Important If you have previously used Kaspersky Online Scanner (before 8th Aug 2006), you will have to uninstall the old version using Add/Remove Programs in Control Panel before you can use the new version.
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings.
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:
Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK.
Now under select a target to scan select My Computer.
The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
Now click on the Save as Text button:
Save the file to your desktop.
Copy and paste that information in your next post please, along with the Ewido log and a new HJT log.
ewido did not save a report after a long scan.
Can't see the whole screen in safe mode.
I'll have to scan again - later
Kaspersky scanner found 3 viruses and 6 infected objects.
——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, September 21, 2006 10:53:41 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 22/09/2006
Kaspersky Anti-Virus database records: 225410
——————————————————————————-
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 60742
Number of viruses found: 3
Number of infected objects: 6 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:44:58
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\WDLog-08062006-142914.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Documents\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Beethoven's Symphony No. 9 (Scherzo).wma Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Music\New Stories (Highway Blues).wma Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst1.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst10.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst11.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst12.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst13.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst14.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst15.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst2.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst3.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst4.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst5.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst6.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst7.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst8.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Music\Sample Playlists\000648E3\Plylst9.wpl Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Desktop.ini Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Blue hills.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\DESKTOP.INI Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Sunset.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Water lilies.jpg Object is locked skipped
C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Winter.jpg Object is locked skipped
C:\Documents and Settings\Grays\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Grays\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\Grays\Desktop\OiUninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\Documents and Settings\Grays\Desktop\OiUninstaller.exe/data0003 Infected: not-a-virus:AdWare.Win32.PurityScan.bu skipped
C:\Documents and Settings\Grays\Desktop\OiUninstaller.exe NSIS: infected - 2 skipped
C:\Documents and Settings\Grays\Local Settings\Application Data\AOL\UserProfiles\All Users\cls\common.cls Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{9D9BC823-CC05-459C-B98B-8447443E21C8} Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Temp\hsperfdata_Grays\2796 Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Temp\~DF2FD2.tmp Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Temp\~DFA886.tmp Object is locked skipped
C:\Documents and Settings\Grays\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Grays\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Grays\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\INDEX.DAT Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\eengine\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0395NAV~.TMP Object is locked skipped
C:\Program Files\Symantec AntiVirus\SAVRT\0541NAV~.TMP Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP183\A0010850.com Infected: Backdoor.Win32.SdBot.xd skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP183\A0010917.exe Infected: Backdoor.Win32.SdBot.xd skipped
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP194\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\7ldgn0nd.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM Object is locked skipped
C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\H323LOG.TXT Object is locked skipped
C:\WINDOWS\SYSTEM32\sеcurity\cemo.exe Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\WBEM\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WIADEBUG.LOG Object is locked skipped
C:\WINDOWS\WIASERVC.LOG Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
Logfile of HijackThis v1.99.1
Scan saved at 11:08:38 PM, on 9/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
You're HJT log looks clean now, just one file to see to from your Kaspersky scan the others are an uninstaller (these are often flagged as they exhibit traits associated with Trojans, and are therefore misdiagnosed by the Heuristics used), and your System Restore Points (these can not re-infect you unless you perform a system restore. We'll clean them out in due course).
OK, Make sure that you can see hidden files and folders.
Click Start.
Click My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab.
Under the Hidden files and folders heading select Show hidden files and folders.
Click Yes to confirm.
Uncheck the Hide file extensions for known file types.
Click OK.
Search for Hidden Files
By default, the Search companion does not search for hidden files. Because of this, you may be unable to find files, even though they exist on the drive.
To search for hidden or system files in Windows XP:
Click Start.
Click Search.
Click All files and folders.
Click More advanced options.
Click to select the Search hidden files and folders check box.
Now find and delete the following file.
C:\WINDOWS\SYSTEM32\7ldgn0nd.ini
How's your computer behaving now? Any problems?
Let me know, and then we can clear out your System Restore points and secure your computer against further infection.
Gary,
I deleted the file you requested.
However, symantec antivirus scan keeps finding:
Adware.purityscan cemo.exe
C:\windows\system32\s?curity
C:\windows\system32\scurit~1
How do I eliminate these once and for all?
Gary,
Here is the ewindo report, however I did not scan in safe mode. In safe mode the desktop screen is bigger than the monitor space and there are no slide bars to move the screen.
Thanks for all your help.
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 5:26:45 PM 9/23/2006
+ Scan result:
C:\Documents and Settings\Grays\Cookies\grays@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@amznshopbop.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\grays@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
C:\Documents and Settings\Grays\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
::Report end
Looks like that got em, is Norton still flagging anything?
If not then your computer looks clean.
Are you still noticing any problems?. If not, it's time to secure your system to prevent against further intrusions.
THESE STEPS ARE VERY IMPORTANT
Lets reset system restore
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to clean the restore points.
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Reboot.
Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
NOTE: only do this ONCE, NOTon a regular basis
We need to re hide system files.
To do so, please follow the steps below:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Put a check by "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Do not show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.
Updating Windows and Internet Explorer
IMPORTANT: You need to update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates.
If you're running Microsoft Office, or any portion thereof, go to Microsoft's Office Update site and make sure you have at least all the critical updates installed. (Free at Microsoft Office Update).
Make your Internet Explorer more secure
From within Internet Explorer click on Tools > Options > Security > Internet > Custom Level.
Make sure these options are set as follows:
Download signed ActiveX controls to Prompt
Download unsigned ActiveX controls to Disable
Initialize and script ActiveX controls not marked as safe to Disable
Installation of desktop items to Prompt
Launching programs and files in an IFRAME to Prompt
Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Press the Apply button and then the OK to exit the Internet Properties page.
The following are free programs that are designed to keep your computer clean. A brief description is included with each item, click on name to go to download site.
Adaware SE Personal
Adaware is a free program. It scans for known spyware on your computer. These scans should be run at least once every two weeks. For more information, see this tutorial
Spybot S & D
Spybot is a scanner like Adaware. It scans for spyware and other malicious programs. It is important to have both Adaware and Spybot on your computer because each program provides unique detection and protection measures. Spybot has preventitive tools that stop programs from even installing on your computer.
To see how to set this up as well as more spybot features, see here
SpywareBlaster
Spyware blaster is a program that stops known malicious activex controls from installing on your computer. It works by changing settings in your registry. It makes "kill bits" in the registry, so that certain activex controls can't install.
If you don't know what activex controls are, see here
IE Spyad
It puts many bad webpages on your restricted zones LIST. This means that you can still view the "bad" webpages, but the webpages can't do certain things (such as use javascripts and cookies). Use IE Spyad for single account computers, and IE Spyad 2 for multi account computers.
Hosts file:
Every version of windows has a hosts file as part of them.
In a very basic sense, they are used to locate webpages.
We can customize a hosts file so that it blocks certain webpages.
However, it can slow down certain computers.
This is why using a hosts file is optional!!
Make sure you read the instructions on how to install the hosts file, here.
If you decide to download the hosts file, the slowdown problems can usually be avoided by following these steps:
Click the start button (at the lower left hand corner of your screen)
Click run
In the dialog box, type services.msc
hit enter, then locate dns client
Highlight it, then double-click it.
On the dropdown box, change the setting from automatic to manual.
Click ok
Use an Anti Virus Software- It's very important that your computer has an anti-virus software running. This alone can save you a lot of trouble with malware in the future. See this link for a LISTing of some, on line & their stand-alone anti virus programs:
Computer Safety On line - LIST of free Anti virus programs
Use a Firewall- I cannot stress enough how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For more info, check this webpage out.
See here to choose one.
Site Advisor This is a utility that can be downloaded and installed. It loads an icon to the taskbar of your browser (versions for IE and Firefox), indicating the trustworthiness of the site you are on. Green for safe, Red for suspicious. Click on the icon to access details that SiteAdvisor has about the site.
Just a final reminder for you.
UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks.
Run Spybot and Adaware regularly. (Once a week minimum)
It is important that you visit http://www.windowsupdate.com regularly. This will ensure you always have the latest security updates installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Once again, please post and tell me how things are going with your system… problems etc.
Gary R
The above is a general post I give when someone's computer is clean. Obviously you have already taken care of some of the issues mentioned, but it is important that you read through them, and address any that you may have missed.
Gary,
I scanned my computer using ewido in safe mode and found the following and quarenteened and deleted them. I even found a new file for purity scan and deleted it. It finally may be gone for good! My question is: Is it necessary to scan in normal mode after scanning in safe mode? It seems redundant. Is safemode more thorough than normal mode?
I deleted combofix and reset everything. I tried to automate disk cleaning, check disk, and defragging at regular intervals to save some time for other things like updating antispyware updates.
Hopefully, my daughter will leave zone alarm on.
Thanks again for your help. I'll probably be back soon!
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 5:10:57 PM 9/25/2006
+ Scan result:
HKU\S-1-5-21-1535245887-1044504659-268624670-1009\Software\aurora -> Adware.BetterInternet : Cleaned with backup (quarantined).
HKU\S-1-5-21-1535245887-1044504659-268624670-1009\Software\intexp -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1535245887-1044504659-268624670-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-4A68-A602-5812EB50A834} -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKU\S-1-5-21-1535245887-1044504659-268624670-1009\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-4A68-A602-5812EB50A834} -> Adware.Virtumonde : Cleaned with backup (quarantined).
HKU\S-1-5-21-1535245887-1044504659-268624670-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -> Downloader.ConHook.l : Cleaned with backup (quarantined).
::Report end
I scanned my computer using ewido in safe mode and found the following and quarenteened and deleted them. I even found a new file for purity scan and deleted it. It finally may be gone for good! My question is: Is it necessary to scan in normal mode after scanning in safe mode? It seems redundant. Is safemode more thorough than normal mode?
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI