View Single Post
Old 06-11-2006, 02:57 AM   #7 (permalink)
Hustler24
Analyst, Security Team
 
Join Date: Mar 2005
Posts: 890
OS: Windows XP Home


We'll have a look at the add/remove list and see if we can remove anything spywere/adware related. WildTangent is one program but there may be others.

Your HJT log is clean now so we'll have to look at other avenues.

-----------------

FILE DELETIONS

Reboot into Safe Mode and delete the following file:

C:\WINDOWS\system32\qos.dll

------------------

DOWNLOADS

Reboot normally.

Download StartDreck

Unzip to its own folder and start the program:
Press 'Config'
Press 'Unmark All'

Check the following boxes only:
Registry -> Run Keys
System/drivers> Running processes
Press 'Ok'

Press 'Save' and select the location to save the log file (default is the same folder as the application)

Post the log in this thread.


------------------

Please download SilentRunners.vbs - Right click & choose Save As... SilentRunners.vbs

Before proceeding, disable any anti-virus or anti-spyware programs that may block/disable scripts

Launch SilentRunners by double-clicking the downloaded file. In the ensuing Window, select 'No' to avoid skipping supplementary searches. Please be patient as the script requires a few minutes to complete.

When it's done, you'll receive the prompt "All Done!". It will create a file called "Startup Programs". Post ALL its contents here in your next reply.

--------------

Download GMER Rootkit Scanner from here.

Unzip it to your Desktop and double-click gmer.exe

Run the program and select the Rootkit tab. Click the Scan button and let the program do its work. It will produce a log. Copy the log using the Copy button and post the log in this thread.

----------------

CREATE UNINSTALL LIST
  • Open Hijack This
  • Click on the "Configure" button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Open Uninstall Manager"
  • Click on the button "Save list"

---------------

So post the Silent Runners log and the StartDreck log in your reply along with the HJT uninstall list and the GMER log.
Hustler24 is offline