Thread: worm_chod.l
View Single Post
Old 06-07-2006, 02:05 PM   #7 (permalink)
Hustler24
Analyst, Security Team
 
Join Date: Mar 2005
Posts: 890
OS: Windows XP Home


SAFE MODE

Please reboot into Safe Mode as described earlier.

UNINSTALLS

Please uninstall the following via Add/Remove:

Need2Find

FILE DELETIONS

Please delete the following folders highlighted in blue:

c:\program files\Need2Find
D:\WINDOWS\TEMP\Adware
D:\Program Files\TBONBin\

REGISTRY FIX

Please download the attached file. Double-click it and open the file inside.

When asked whether you would like to merge with the registry, click Yes.

This will remove some malware files from the registry.

DELETE COOKIES

Clear your IE cookies. Start>Settings>Control Panel>Internet Options>General tab>under Temporary files, click on Delete Cookies.

ONLINE SCAN

Reboot into Normal mode

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Answer Yes, when prompted to install an ActiveX component.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Post the Kaspersky log and a new HJT log.

How is your system performing now?
Attached Files
File Type: zip icemaid.zip (227 Bytes, 2 views)

Last edited by sUBs; 06-07-2006 at 07:22 PM.
Hustler24 is offline