spyware sucks

Reply

Join Date: Jul 2005
Posts: 642
Reputation: swatkat is an unknown quantity at this point 
Solved Threads: 50
swatkat's Avatar
swatkat swatkat is offline Offline
Small Town Boy

Re: spyware sucks

 
0
  #21
Nov 15th, 2005
Hi,
Those logs look clean. We have to search for the "baddies"!!


Try this, open Internet Explorer, go to Tools Menu > Internet Options. Here, click "Advanced" tab and uncheck the option "Enable third party browser extension" and click "Apply" and "OK". Close IE.


Download SpywareBlaster and install it. Run it and click "Enable All Protection" and then close.


Perform a scan at Kaspersky Web scanner (click the button "Kaspersky Online Scanner") and save its log. Please post back its log.

Also, post back whether you get the pop-ups or not.
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 642
Reputation: swatkat is an unknown quantity at this point 
Solved Threads: 50
swatkat's Avatar
swatkat swatkat is offline Offline
Small Town Boy

Re: spyware sucks

 
0
  #22
Nov 15th, 2005
Hi,
Download KillBox.zip and extract it to a folder. Run KillBox.exe and select the options "End explorer shell while killing file" and "Standard file kill". Next, copy the below mentioned file name completely and paste it in the Full path of the file to delete text box in KillBox.

C:\WINDOWS\prK7N

Once this filename is copied to the KillBox, click the button which has a "white coloured cross on red background" to delete the file.
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
Reply With Quote Quick reply to this message  
Join Date: Oct 2005
Posts: 14
Reputation: superdairyboy is an unknown quantity at this point 
Solved Threads: 0
superdairyboy superdairyboy is offline Offline
Newbie Poster

Re: spyware sucks

 
0
  #23
Nov 19th, 2005
Here is the Kaspersky Scan

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Saturday, November 19, 2005 11:11:19
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 19/11/2005
Kaspersky Anti-Virus database records: 150874
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 114632
Number of viruses found: 10
Number of infected objects: 22
Number of suspicious objects: 15
Duration of the scan process: 6955 sec

Infected Object Name - Virus Name
C:\Aw2000\Attachments\Business.zip/1.exe Infected: Email-Worm.Win32.Bagle.ei
C:\Aw2000\Attachments\Business.zip Infected: Email-Worm.Win32.Bagle.ei
C:\Aw2000\Attachments\Connect.zip/connect.exe Infected: Trojan-Spy.Win32.Goldun.ec
C:\Aw2000\Attachments\Connect.zip Infected: Trojan-Spy.Win32.Goldun.ec
C:\Aw2000\Attachments\email_photo.zip/Packed-jpeg_photoDat.exe Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\email_photo.zip Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\email_photo1.zip/Packed-jpeg_photoDat.exe Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\email_photo1.zip Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\email_photo2.zip/Packed-jpeg_photoDat.exe Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\email_photo2.zip Infected: Email-Worm.Win32.Sober.t
C:\Aw2000\Attachments\packed-password_text.zip/mail-packed_password.exe Infected: Email-Worm.Win32.Sober.z
C:\Aw2000\Attachments\packed-password_text.zip Infected: Email-Worm.Win32.Sober.z
C:\Aw2000\Attachments\sms_text.zip/5.exe Infected: Email-Worm.Win32.Bagle.ek
C:\Aw2000\Attachments\sms_text.zip Infected: Email-Worm.Win32.Bagle.ek
C:\Aw2000\Attachments\text_sms.zip/5.exe Infected: Email-Worm.Win32.Bagle.ek
C:\Aw2000\Attachments\text_sms.zip Infected: Email-Worm.Win32.Bagle.ek
C:\Crystal Art Software\Crystal FTP\TSUninstaller.exe Suspicious: Type_Win32
C:\Crystal Art Software\Crystal FTP\uninstal.exe Suspicious: Type_Win32
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <support_ref_70073898@ebay.com>][Date Sat, 12 Nov 2005 14:19:54 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <support_ref_70073898@ebay.com>][Date Sat, 12 Nov 2005 14:19:54 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\My Documents\Bussiness\E-Books\Bussiness Ideas and Information Work at home\E-Biz Tips & Tricks.exe Suspicious: Type_Win32
C:\My Documents\Bussiness\E-Books\Bussiness Ideas and Information Work at home\E-Business Secrets.exe Suspicious: Type_Win32
C:\My Documents\Bussiness\E-Books\Self Imrovement Memory Speed reading and More\Creative IQ.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\components\talkback.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\netscp6.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\regxpcom.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\ren8dot3.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\Setup\N6SETUP[1].EXE Suspicious: Type_Win32
C:\Netscape\Netscape 6\uninstall\N6Uninst.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\xpicleanup.exe Suspicious: Type_Win32
C:\pmw2\INSTALL.EXE Suspicious: Type_Win32
C:\pmw2\MSRUN.EXE Suspicious: Type_Win32
C:\pmw2\PMWURL.EXE Suspicious: Type_Win32
C:\WINDOWS\rfwnwok.exe Infected: Trojan-Clicker.Win32.VB.ij
C:\WINDOWS\system32\fran-hot.exe Infected: Trojan-Dropper.Win32.Agent.abb
C:\WINDOWS\system32\skefgwmi.dll Infected: Trojan.Win32.Crypt.t

Scan process completed.


Brian
Reply With Quote Quick reply to this message  
Join Date: Oct 2005
Posts: 14
Reputation: superdairyboy is an unknown quantity at this point 
Solved Threads: 0
superdairyboy superdairyboy is offline Offline
Newbie Poster

Re: spyware sucks

 
0
  #24
Nov 19th, 2005
and yes the pop ups are still here
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 642
Reputation: swatkat is an unknown quantity at this point 
Solved Threads: 50
swatkat's Avatar
swatkat swatkat is offline Offline
Small Town Boy

Re: spyware sucks

 
0
  #25
Nov 21st, 2005
Hi,

Boot in Safe Mode. Then delete these files:-

C:\WINDOWS\rfwnwok.exe
C:\WINDOWS\system32\fran-hot.exe
C:\WINDOWS\system32\skefgwmi.dll
C:\Aw2000\Attachments\Business.zip
C:\Aw2000\Attachments\Connect.zip
C:\Aw2000\Attachments\email_photo.zip
C:\Aw2000\Attachments\email_photo1.zip
C:\Aw2000\Attachments\email_photo2.zip
C:\Aw2000\Attachments\packed-password_text.zip
C:\Aw2000\Attachments\sms_text.zip
C:\Aw2000\Attachments\text_sms.zip
C:\Crystal Art Software\Crystal FTP\TSUninstaller.exe
C:\Crystal Art Software\Crystal FTP\uninstal.exe
C:\My Documents\Bussiness\E-Books\Bussiness Ideas and Information Work at home\E-Biz Tips & Tricks.exe
C:\My Documents\Bussiness\E-Books\Bussiness Ideas and Information Work at home\E-Business Secrets.exe
C:\My Documents\Bussiness\E-Books\Self Imrovement Memory Speed reading and More\Creative IQ.exe


Restart to Normal Mode. Upload and scan the below mentioned files at http://virusscan.jotti.org/ and if they are found infected, please delete them:-
C:\pmw2\INSTALL.EXE
C:\pmw2\MSRUN.EXE
C:\pmw2\PMWURL.EXE


After this, please run a scan at Kaspersky Online Scanner again and post back its log file.
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
Reply With Quote Quick reply to this message  
Join Date: Oct 2005
Posts: 14
Reputation: superdairyboy is an unknown quantity at this point 
Solved Threads: 0
superdairyboy superdairyboy is offline Offline
Newbie Poster

Re: spyware sucks

 
0
  #26
Nov 24th, 2005
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Thursday, November 24, 2005 08:32:59
Operating System: Microsoft Windows XP Professional, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 24/11/2005
Kaspersky Anti-Virus database records: 151544
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
Z:\

Scan Statistics:
Total number of scanned objects: 115350
Number of viruses found: 8
Number of infected objects: 211
Number of suspicious objects: 10
Duration of the scan process: 7762 sec

Infected Object Name - Virus Name
C:\Aw2000\Attachments\account-details.zip/account-details.doc .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-details.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-details1.zip/account-details.txt .scr Infected: Email-Worm.Win32.Doombot.g
C:\Aw2000\Attachments\account-details1.zip Infected: Email-Worm.Win32.Doombot.g
C:\Aw2000\Attachments\account-password.zip/account-password.txt .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-password.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-report.zip/account-report.doc .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-report.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-report1.zip/account-report.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\account-report1.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\downloadm.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm10.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm10.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm8.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm8.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm9.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\downloadm9.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\email-details.zip/email-details.htm .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\email-details.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\email-details1.zip/email-details.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\email-details1.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\gxmpjx.zip/gxmpjx.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\gxmpjx.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\h.zip/check.jpg .exe Infected: Trojan-Spy.Win32.Goldun.et
C:\Aw2000\Attachments\h.zip Infected: Trojan-Spy.Win32.Goldun.et
C:\Aw2000\Attachments\id.zip/check.jpg .exe Infected: Trojan-Spy.Win32.Goldun.et
C:\Aw2000\Attachments\id.zip Infected: Trojan-Spy.Win32.Goldun.et
C:\Aw2000\Attachments\important-details.zip/important-details.htm .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\important-details.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\important-details1.zip/important-details.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\important-details1.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list166.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list166.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list496.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list496.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list873.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\list873.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail10.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail10.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail8.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail8.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail9.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail9.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext10.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext10.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext11.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext11.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext12.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext12.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext13.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext13.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext8.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext8.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext9.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mailtext9.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\mail_body7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list293.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list293.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list884.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\question_list884.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\readme.zip/readme.txt .pif Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\readme.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\reg_pass-data.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data10.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data10.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data11.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data11.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data12.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data12.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data13.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data13.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data8.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data8.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data9.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass-data9.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass1.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass1.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass10.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass10.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass11.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass11.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass2.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass2.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass3.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass3.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass4.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass4.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass5.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass5.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass6.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass6.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass7.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass7.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass8.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass8.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass9.zip/File-packed_dataInfo.exe Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\reg_pass9.zip Infected: Email-Worm.Win32.Sober.y
C:\Aw2000\Attachments\sesjjz.zip/sesjjz.txt .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\sesjjz.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\stb.zip/stb.txt .exe Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\stb.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\updated-password.zip/updated-password.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\updated-password.zip Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\updated-password1.zip/updated-password.htm .scr Infected: Email-Worm.Win32.Doombot.f
C:\Aw2000\Attachments\updated-password1.zip Infected: Email-Worm.Win32.Doombot.f
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <support_ref_70073898@ebay.com>][Date Sat, 12 Nov 2005 14:19:54 +0100]/UNNAMED/html Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx/[From eBay <support_ref_70073898@ebay.com>][Date Sat, 12 Nov 2005 14:19:54 +0100]/UNNAMED Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Documents and Settings\dairyboy\Local Settings\Application Data\Identities\{39F294CD-251A-41F1-BC8A-B5AB9ABA061B}\Microsoft\Outlook Express\Deleted Items.dbx Infected: Trojan-Spy.HTML.Bayfraud.hn
C:\Netscape\Netscape 6\components\talkback.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\netscp6.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\regxpcom.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\ren8dot3.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\Setup\N6SETUP[1].EXE Suspicious: Type_Win32
C:\Netscape\Netscape 6\uninstall\N6Uninst.exe Suspicious: Type_Win32
C:\Netscape\Netscape 6\xpicleanup.exe Suspicious: Type_Win32
C:\pmw2\INSTALL.EXE Suspicious: Type_Win32
C:\pmw2\MSRUN.EXE Suspicious: Type_Win32
C:\pmw2\PMWURL.EXE Suspicious: Type_Win32
C:\WINDOWS\offun.exe Infected: Trojan-Downloader.Win32.VB.nw
C:\WINDOWS\system32\swpmpapi.exe Infected: Trojan.Win32.Crypt.t

Scan process completed.
Reply With Quote Quick reply to this message  
Join Date: Jul 2005
Posts: 642
Reputation: swatkat is an unknown quantity at this point 
Solved Threads: 50
swatkat's Avatar
swatkat swatkat is offline Offline
Small Town Boy

Re: spyware sucks

 
0
  #27
Nov 24th, 2005
Hi,

Boot in Safe Mode. Please delete these two files (either manually or using KillBox):-
C:\WINDOWS\offun.exe
C:\WINDOWS\system32\swpmpapi.exe


Also, a lot of attachments in software AW2000 are infected with viruses. Delete all the files inside C:\Aw2000\Attachments folder.


Go to Start > Search. Here click "All files and folders" in the left pane. Next, click on "More advanced options". Here select the options "Search system folders", "Search hidden files and folders" and "Search subfolders". Next, type/copy the below mentioned filename and search for it, if you find it, right-click on it and click delete:-
Deleted Items.dbx


Restart to Normal Mode. I think you dont have an Antivirus software. Its highly essential. If you are not having one, you can download and install AntiVir. Its a very good Antivirus and its free too.
Please post back whether you receive any pop-ups or not.
"Only two things are infinite, the universe and human stupidity, and I'm not sure about the former."
-Albert Einstein.
Reply With Quote Quick reply to this message  
Reply

This thread is more than three months old.
Perhaps start a new thread instead?
Message:



Similar Threads
Other Threads in the Viruses, Spyware and other Nasties Forum


Views: 6904 | Replies: 26
Thread Tools Search this Thread



Tag cloud for Viruses, Spyware and other Nasties
About Us | Contact Us | Advertise | DaniWeb | Acceptable Use Policy | RSS Feed

©2003 - 2009 DaniWeb® LLC