Thread: virsuses
View Single Post
Old 10-11-2005, 06:21 PM   #9 (permalink)
sUBs
Asst Manager Security, Expert Analyst, Moderator, Security Team; Rangemaster, Moderator, TSF Academy
 
sUBs's Avatar
 
Join Date: May 2005
Posts: 24,353
OS: N/A


Follow the instructions outlined here to clear Sun Java's cache.



Uninstall these programs, if present, using Add/Remove Programs:

NewNet /NewDotNet
Quick Search




Have HijackThis fix these entries:

O4 - HKLM\..\Run: [ipea32.exe] C:\WINDOWS\system32\ipea32.exe
O4 - HKLM\..\Run: [winue32.exe] C:\WINDOWS\system32\winue32.exe




Next, locate & delete these files/folders:

C:\PROGRAM FILES\NewDotNet
C:\PROGRAM FILES\QuickSearch
C:\spe
C:\WINDOWS\inetdim



Select all the filenames below & then right-click & select Copy
  • C:\WINDOWS\SYSTEM32\sdkag32.exe
    C:\Documents and Settings\Patrick\Favorites\SITES ABOUT\Ab scissor.url
    C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho
    C:\Documents and Settings\Patrick\Favorites\Free Online Dating.url
    C:\Documents and Settings\Patrick\Favorites\Only sex website.url
    C:\WINDOWS\sepsd.bin
    C:\WINDOWS\smdat32a.sys
    C:\spe
    C:\WINDOWS\inetdim
    C:\WINDOWS\system32\ipea32.exe
    C:\WINDOWS\system32\winue32.exe
Launch KillBox.exe
Go to the File menu, and choose Paste from Clipboard
Select the following options:
  • delete on Reboot
Then, click on the dropdown menu next to Full Path of File to Delete field.
Verify that the filenames you pasted are found there
Click the RED X button.
Click Yes at the Delete on Reboot prompt.
Click Yes at the 'Pending Operations prompt'.


Post a new HJT log after you have rebooted.
__________________

Question - what have you done for the community today?
sUBs is offline