Thread: MSN Spyware
View Single Post
Old 10-19-2008, 11:14 AM   #2 (permalink)
Blade81
Visiting Teacher/Analyst, Security Team
 
Blade81's Avatar
 
Join Date: Jun 2008
Location: Finland
Posts: 709
OS: Win XP, Vista 32-bit, Win7 64-bit


Re: MSN Spyware

Hi

Start hjt, do a system scan, check:
O23 - Service: bcveServ (aiokei2a0) - Unknown owner - C:\WINDOWS\system32\quidyl.exe (file missing)

Close browsers and fix checked.

Creating & executing batch file
-------------------------------

Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop. (If you are still unsure on how to do this there is a little tutorial with pictures here)
@echo off
sc stop aiokei2a0
sc delete aiokei2a0

Double-click on fixes.bat file to execute it.

Delete following file if found:
C:\WINDOWS\system32\quidyl.exe


Reboot.


Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

Double-click ATF Cleaner.exe to open it

Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache

*The other boxes are optional*
Then click the Empty Selected button.

If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

Click Exit on the Main menu to close the program.



Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Please post contents of that file & a fresh hjt log in your next reply.
__________________

Microsoft MVP Consumer Security 2008 2009
ASAP & UNITE member since 2006
Blade81 is offline