View Single Post
Old 05-07-2008, 05:10 AM   #5 (permalink)
nasdaq
Analyst, Security Team
 
Join Date: Apr 2007
Location: Montreal, QC. Canada
Posts: 101
OS: Windows 2000 Pro.


Re: Antispyware-reviews.biz Adware

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.

Optional - VIEWPOINT MANAGER
Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546
Additional info: http://vil.nai.com/vil/content/v_137262.htm

I suggest you remove the program now.
Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
  • Viewpoint Toolbar
Fix the items identified in the HijackThis log below. Your call.
*/*

Open notepad and copy/paste the text in the quote box below into it:

Code:
File::
C:\WINDOWS\system32\nwvohgxs.exe
C:\WINDOWS\system32\ovapkbgt.exe

Folder::
C:\Documents and Settings\All Users\Application Data\erotejex

Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hcdkegug"=-
"wjqvlwup"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"wYMZDa6bz5"=-
Save this as CFScript on your desktop.



Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a fresh copy of HijackThis.
__________________
nasdaq is offline   Reply With Quote