Disinfecting a PC… part 2



Ok, the last post got a bit long with the hijackthis log, but I wanted to include the whole picture. I put a few comments in, but thought it might be useful to include the notes I took at the time. For starters I leave it unplugged from the network. (There is no network card in this machine.) It’s important when working on an infested PC to leave it isolated so that it can’t continue to spread viruses or spam or whatever it may be doing. Assume if it’s infested with something that it could be spewing out bad stuff. If you must, isolated it and prevent it from routing to the outside world… the safest is usually to leave the cable unplugged for the initial look over.


Left net cable off, Booted and looked – installer icon in system tray which disappeared before I could get a tooltip for it. Looks spywareish… webshots (didn’t they bundle with spyware at some point?) Looking at msconfig – jawa32 looks suspect. SurfSidekick 2 (ssk.exe), ssdpsrv.exe (???), ylgril.exe, C:Program FilesVBouncerVBouncerInner.exe /S, C:WINDOWSSYSTEMpuswxc.exe, c:windowssystemsaie.exe, C:WINDOWSGuqvqmm.exe, C:WINDOWSXecrtyr.exe, C:WINDOWSaqadcup.exe, C:WINDOWSgoidr.exe, C:Program FilesCommon Filesslmssslmss.exe,C:PROGRA~1BMCENT~1BMLauncher.exe.(?)

So, in the above I’ve highlighted the running processes or startup entries that I don’t recognize right off, or don’t seem normal.

Running hijack this… and analyzing… (Log was included in previous post.)
Several BHO’s
jawa32.exe looks to be a trojan backdoor.agent.bg ??
Looks fairly infested… installing AVG and updating.

Got spybot S&D, ad-aware and bhodemon in the wings…. just in case…

AVG failed install… It gave an error accessing the registry…

Local machine: installation failed
Initialization:
Error: Checking of state of the item registry key HKLMSOFTWAREMicrosoftWindowsCurrentVersionAvg7RunOnceParams failed.
The configuration registry database is corrupt. (1009)

Time to use a working networked pc…

Related Posts

Blog Traffic Exchange Related Posts
  • Windows XP Unable to Login After Cleaning Out Rogue Antivirus This article may come in handy if you are out there battling the latest rogue du jour. Occasionally I have been through a cleaning process for these rogues and got to a point where the scanner had run and cleaned things out (whether it was malwarebytes antimalware or superantispyware.) It......
  • Zotob worm bites big media outlets According to several reports there are several big media outlets seeing what is reported as the zotob worm which exploits a Microsoft Windows vulnerability (MS05-039) disclosed last week. There seems to be no better way for something to make the news than for it to affect the companies that bring......
  • Windows Police Pro Yes folks, it's Windows Police Pro, the gift that keeps on giving apparently. It's crawled back into Googles top searches tonight. If you want to see how to remove it look at Windows Police Pro Removal, you may be interested in Who is behind Windows Police Pro and probably will......
Blog Traffic Exchange Related Websites
  • Fix Windows Registry Error For many people who do not know that their computer has on it, a registry cleaner can be a great idea. Oftentimes, people have computers for a year and two, and then begin to experience slower speeds when they are using it. This is not usually a problem with the......
  • Experiencing Slow Pc Performance? It seems that many people today can no longer live without their personal computer. However, despite its extreme demand these days, many pc owners are experiencing slow pc performance. Don't despair because there are ways to improve the performance of your pc. Registry files found in your computer are vital.......
  • Pc Repair Using Registry Cleaners How can you speed up your pc when it starts slowing down? For you to fix this issue, you need to understand why it happens. Generally, slow operations on a PC are caused by a problem within the windows registry. This is the devote the pc system where all of......
PDF24    Send article as PDF   

Similar Posts


See what happened this day in history from either BBC Wikipedia
Search:
Keywords:
Amazon Logo

Comments are closed.


Switch to our mobile site