View Single Post
  #3  
Old 01-25-2005, 06:05 PM
Mobo's Avatar
Mobo Mobo is offline
Thinking outside the box
 
Join Date: Sep 2004
Location: Cape Breton
Posts: 4,587
Send a message via ICQ to Mobo Send a message via AIM to Mobo Send a message via MSN to Mobo Send a message via Yahoo to Mobo Send a message via Skype™ to Mobo
Hi and welcome aboard..

First I would like you to rescan once again with hijack, insert a check next to each of the following, close all other open browser windows and click "fix checked"

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank

R3 - Default URLSearchHook is missing

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)

O4 - HKLM\..\Run: [Services] C:\DOCUME~1\Philip\LOCALS~1\Temp\services.exe



Then reboot into safe mode http://www.spyware911.net/safemode.htm


Open windows explorer, find then delete:
C:\DOCUME~1\Philip\LOCALS~1\Temp\services.exe


Reboot,
Download TDS-3 trojan scanner from http://tds.diamondcs.com.au/index.php?page=download

Then you will need to manually update it so follow the instructions given here
http://tds.diamondcs.com.au/index.php?page=update

Now open the program, pause until its finished its mini test then click system testing / full scan

If anything is found, right click and select delete to each when the scan completes itself.

Rescan with hijack then post a fresh log please.
Reply With Quote