Hi raycheality
Please read through the instructions before you start (you may want to print this out).
Please set your system to show all files; please see here if you're unsure how to do this.
Please download and install AD-Aware se.
[urlhttp://russelltexas.com/malware/adawarese/adawarese.htm]Check Here on how setup and use it[/url] - please make sure you update it first. Don't run yet.
Download Pocket Killbox and unzip it; save it to your Desktop.
Please download SpyBot V1.4 http://www.majorgeeks.com/download2471.html Update the program then run it.
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Please go to the following website
Please download Nailfix
Unzip it to the desktop but please do NOT run it yet.
Download APT
Open apt and search in the window for the C:\WINDOWS\system32\beyqve.exe r.
Open your C:\Windows\system32 folder and search for the bad file. Don't delete it yet, just leave the system32 folder open so you can see the bad file.
In apt again, Select the bad process and Click Kill3
Then immediately delete the bad file from your system32 folder. C:\WINDOWS\system32\beyqve.exe r.
Reboot into Safe Mode: Please see here if you are not sure how to do this.
Run Ewido full scan. Save the scan.log.
Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch and delete all the files in that folder.<--XP only
Please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.
Then please run Ewido, and run a full scan. Save the logfile from the scan.
Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O4 - HKLM\..\Run: [klbitjc] C:\WINDOWS\system32\beyqve.exe r
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1822f4ef29e76b...ip/RdxIE601.cab
O16 - DPF: {7D40ADF2-AD68-4959-ACEC-DA96BF5E6EB7} (SpyBouncer.SBDownloader) - http://spywareremover.spybouncer.com/downloader.ocx
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\cmbcatq.dll (file missing)
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\mbxclu.dll (file missing)
Click on Fix Checked when finished and exit HijackThis.
Run Ad-aware se let remove all it finds
Using Windows Explorer, locate the following files/folders, and delete them:
C:\Program Files\CxtPls<--Delete this file
C:\WINDOWS\Helper100.dll<--Delete this file
Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:
Run killbox and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
c:\windows\system32\itrusk.exe
C:\WINDOWS\dsr.dll
C:\WINDOWS\Nail.exe
C:\WINDOWS\enhtb.dll
C:\WINDOWS\dsr.dll
C:\WINDOWS\Ockpwtmc.dll
C:\WINDOWS\System32\lvhno.dll
C:\WINDOWS\av.exe
C:\WINDOWS\System32\lvhnoc.exe
C:\WINDOWS\System32\sqlsvpia.exe
C:\WINDOWS\System32\hgor.exe
Let the system reboot as normal.
Please run the following free, online virus scans.
http://www.pandasoftware.com/activescan/co...n_principal.htm
Please post the log From Panda virus scan. We will need them to remove previous infections that have left files on your system.
Run HijackThis and post the new log.
Kc :grin:
Please read through the instructions before you start (you may want to print this out).
Please set your system to show all files; please see here if you're unsure how to do this.
Please download and install AD-Aware se.
[urlhttp://russelltexas.com/malware/adawarese/adawarese.htm]Check Here on how setup and use it[/url] - please make sure you update it first. Don't run yet.
Download Pocket Killbox and unzip it; save it to your Desktop.
Please download SpyBot V1.4 http://www.majorgeeks.com/download2471.html Update the program then run it.
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files. Do NOT run a scan yet.
Please go to the following website
Please download Nailfix
Unzip it to the desktop but please do NOT run it yet.
Download APT
Open apt and search in the window for the C:\WINDOWS\system32\beyqve.exe r.
Open your C:\Windows\system32 folder and search for the bad file. Don't delete it yet, just leave the system32 folder open so you can see the bad file.
In apt again, Select the bad process and Click Kill3
Then immediately delete the bad file from your system32 folder. C:\WINDOWS\system32\beyqve.exe r.
Reboot into Safe Mode: Please see here if you are not sure how to do this.
Run Ewido full scan. Save the scan.log.
Clear out the files in the Prefetch folder. Go to start> run> type into the box Prefetch and delete all the files in that folder.<--XP only
Please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.
Then please run Ewido, and run a full scan. Save the logfile from the scan.
Please go offline, close all browsers and any open Windows, making sure that only HijackThis is open. Scan and when it finishes, put an X in the boxes, only next to these following items:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O4 - HKLM\..\Run: [klbitjc] C:\WINDOWS\system32\beyqve.exe r
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1822f4ef29e76b...ip/RdxIE601.cab
O16 - DPF: {7D40ADF2-AD68-4959-ACEC-DA96BF5E6EB7} (SpyBouncer.SBDownloader) - http://spywareremover.spybouncer.com/downloader.ocx
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: IPConfTSP - C:\WINDOWS\system32\cmbcatq.dll (file missing)
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\mbxclu.dll (file missing)
Click on Fix Checked when finished and exit HijackThis.
Run Ad-aware se let remove all it finds
Using Windows Explorer, locate the following files/folders, and delete them:
C:\Program Files\CxtPls<--Delete this file
C:\WINDOWS\Helper100.dll<--Delete this file
Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure all are checked and then press *ok* to remove:
Run killbox and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.
The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.
c:\windows\system32\itrusk.exe
C:\WINDOWS\dsr.dll
C:\WINDOWS\Nail.exe
C:\WINDOWS\enhtb.dll
C:\WINDOWS\dsr.dll
C:\WINDOWS\Ockpwtmc.dll
C:\WINDOWS\System32\lvhno.dll
C:\WINDOWS\av.exe
C:\WINDOWS\System32\lvhnoc.exe
C:\WINDOWS\System32\sqlsvpia.exe
C:\WINDOWS\System32\hgor.exe
Let the system reboot as normal.
Please run the following free, online virus scans.
http://www.pandasoftware.com/activescan/co...n_principal.htm
Please post the log From Panda virus scan. We will need them to remove previous infections that have left files on your system.
Run HijackThis and post the new log.
Kc :grin: