Open NotePad, and copy the contents of the below "Code" box:-
cd %windir%
attrib -s -r -h ALCXMNTR.EXE
attrib -s -r -h msnmsgr.exe
attrib -s -r -h fw_304.exe
attrib -s -r -h messenger.exe
del ALCXMNTR.EXE
del msnmsgr.exe
del fw_304.exe
del messenger.exe
cd system32
attrib -s -r -h szxfv.exe
attrib -s -r -h swqqeadt.exe
attrib -s -r -h cdqtkuc.exe
attrib -s -r -h msnmsgr.exe
attrib -s -r -h messenger.exe
del szxfv.exe
del swqqeadt.exe
del cdqtkuc.exe
del msnmsgr.exe
del messenger.exeGo to File Menu >Save As, and save the file with the name Test.bat and exit from NotePad.
Please print or save this Webpage.
Make Windows to show all files:-
Go to Start > My Computer.
Go to Tools menu, click Folder Options (Folder Option will be in View Menu in Win98).
Uncheck Hide protected operating system files.
Then, click to select the option Show hidden files and folders.
Click Apply and then click OK to exit.
Download these Tools and Install them:-
CCleaner
TrojanHunter
Download FxGaoBot , removal tool to remove GaoBot worm. Do not run it now.
Reboot in Safe Mode. Restart (or switch ON) the PC. Then, keep tapping the F8 Key. From the menu that will be displayed, out of which choose Safe Mode and press Enter.
Run HijackThis and click Do only a System scan.
Then put a check mark infront of below listed entries:-
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://gb10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-gb10.hpwis.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.co.uk/0SEENGB/SAOS01
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-gb10.hpwis.com/
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {8E13DDE1-E013-47ec-9C4C-27C2F78BDD26} - C:\WINDOWS\system32\req.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\swqqeadt.exe
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\cdqtkuc.exe
O4 - HKLM\..\Run: [NVIDIA Video drivers] video_32D.exe
O4 - HKLM\..\Run: [restrictanonymous]
O4 - HKLM\..\Run: [Outlook Express] rtdkz.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Communicator] C:\WINDOWS\fw_304.exe /i
O4 - HKLM\..\RunServices: [Win32 USB2 Driver] smsc.exe
O4 - HKLM\..\RunServices: [NVIDIA Video drivers] video_32D.exe
O4 - HKLM\..\RunServices: [Outlook Express] rtdkz.exe
O4 - HKCU\..\Run: [Win32 USB2 Driver] smsc.exe
O4 - HKCU\..\Run: [msn] msnmsgr.exe
O4 - HKCU\..\Run: [NVIDIA Video drivers] video_32D.exe
O4 - HKCU\..\Run: [Msn Messenger Service] messenger.exe
O4 - HKCU\..\Run: [Notn] C:\Documents and Settings\Owner\Application Data\eber.exe
O4 - HKCU\..\Run: [Outlook Express] rtdkz.exe
O4 - HKCU\..\RunServices: [Outlook Express] rtdkz.exe
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZSzeb029
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) - http://sib1.od2.com/common/Member/ClientInstall/9.20.0002/OCI/setup.exe
O20 - Winlogon Notify: req - C:\WINDOWS\system32\req.dll (file missing)
O23 - Service: Win32 USB2 Driver (Microsoft Config) - Unknown owner - C:\WINDOWS\System32\smsc.exe" -netsvcs (file missing)
Close all other open programs except Hijackthis and click the button Fix Checked in HijackThis.
Run the FxGaoBot.exe. After this, double-click on the Test.bat file, a small DOS window should open and close automatically.
Then delete these files manually, using Windows Search feature:-
video_32D.exe
rtdkz.exe
smsc.exe
C:\Documents and Settings\Owner\Application Data\eber.exe
Run these applications in the following order and remove the bad things they may find.
CCleanerClick "Options" button and here go to "Settings" tab and uncheck the option "Only delete files in Windows Temp folder older than 48 hours".
Click OK to exit from the Options.
Finally click "Run Cleaner".
TrojanHunterSelect all the Hard Disk partitions.
Click "Full Scan", remove any trojan it may find.
Reboot to Normal Mode and run HijackThis again. Then click Do a System scan and save log, and post the fresh log. Also, post whether FxGaoBot, TrojanHunter found anything or not.