View Single Post
Old 08-01-2006, 10:26 PM   #8 (permalink)
MoralTerror
Analyst, Security Team
 
MoralTerror's Avatar
 
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp


Hi paulmath

Quote:
Originally Posted by paulmath
Could this be a power supply issue? Over heating?
We still have some cleaning to do to rule out malware. Once the PC is clean we will let you know.

You are still running HijackThis from a temporary location. Its important to be in a permanent directory as it creates backups we may need later. Please create a folder at c:\ and call it HJT. Right click on C:\DOCUME~1\ALICIA~1\LOCALS~1\Temp\Rar$EX00.281\HijackThis.exe and extract it to C:\HJT

--------------------------------------

I have attached a file to this post - regdel.zip Download this file to your desktop. Double click on the zip folder, then double click on the delete.reg file within. Click yes to allow it to merge into your registry.You can delete the file afterwards.




--------------------------------------

Open Control Panel > Add/Remove Programs and uninstall the following programs (If the exist)

MyWay
Need2Find


Delete the following Files and Folders (if they still exist)

c:\windows\smdat32a.sys
c:\program files\MyWay
c:\program files\Need2Find


--------------------------------------

Perform an online scan with Internet Explorer with

Kaspersky WebScanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    • Extended Scan
    • Scan Options:
    • Scan Archives
      Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
    • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Take note the names and locations of any file it detects but fails to clean.

* Turn off the real time scanner of any existing antivirus program while performing the online scan

--------------------------------------
Required Logs

Kaspersky report
new HijackThis log
MoralTerror is offline