View Single Post
Old 06-18-2006, 08:47 PM   #8 (permalink)
Ried
Assistant Manager, TSF Academy; Moderator/Analyst Security Team
 
Ried's Avatar
 
Join Date: Jan 2005
Location: Ohio
Posts: 27,082
OS: WinXP and Vista


Hello anksmashpunk,

I don't like the fact that FixWareout didn't run properly nor Panda's failure to detect howiper.exe.

Download this file - Find3M.zip
It's important that you extract the contents to a new folder. Do not run it yet.

Download WinPFind and extract it to your C:\ folder. This will create a folder called WinPFind in the C:\ folder. Do Not run it yet.

-------------------------------------

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Use the up arrow key to highlight Safe Mode and press Enter.

-------------------------------------

Delete the following files:

C:\WINDOWS\SYSTEM32\csfti.exe
C:\WINDOWS\SYSTEM32\dmven.exe
C:\WINDOWS\SYSTEM32\howiper.exe


-------------------------------------

Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more.! Once the Scan is Complete it will make a txt file (log) of what was found. Save that log and post it here.

-------------------------------------

Restart one more time back into Normal Mode.

-------------------------------------

Double click on Find3M.bat & it shall produce a logfile for you to post back here along with the WinPFind .txt
__________________

Member of ASAP since 2005
Member of UNITE since 2006

"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."
Ried is offline