danielwebb
asked on
Surf Sidekick is screwing up my 200 server station and i can't remove it! HELP!!!!
hey guys my boss's kids were looking at porn on the server computer which they have repeatedly been told not to use. anyway they got some spyware on there called surf sidekick 3 and i can't get it off. I even tried deleting the registry keys but they keep coming back. Windows defender can't remove it either. Now It is displaying error messages when it boots up. It says one or more drivers or services failed to start check event log. When i check the even log it says the lpd service failed to start and it also says something about the network adapter not working. The internet has stopped working even though it is showing an open connection with the router and the device manager says the network adapter is working properly. What should i do?
Aside from what war1 said I recommened Ad-Aware SE, its free and its incredibly effective. Do a full scan and your problem will be solved. Here's the link:
http://www.lavasoft.de/software/adaware/
http://www.lavasoft.de/software/adaware/
danielwebb,
We have not heard from you. Did any comment help you solve your problem? Do you have any more question? If an Expert helped you, please accept his/her answer above with an excellent or good grade.
Thanks, war1
We have not heard from you. Did any comment help you solve your problem? Do you have any more question? If an Expert helped you, please accept his/her answer above with an excellent or good grade.
Thanks, war1
ASKER
well i got the surf sidekick off but now mcafee is detecting a pup called adware-clickspring in c:\program files\-dobe\chkdsk.exe, and a trojan named downloader-ev in c:\winnt\system32\A-pPatch \cmd.exe and it can't clean quarantine or delete them
danielwebb,
1. If these trojans are in System Restore, antivirus programs cannot delete them. Disable and Enable System Restore
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
2. If no joy, antivirus programs are designed to remove virus, not mailware. You need mailware removers.
Ewido to remove trojans
http://www.ewido.net/en/
and
Spy Sweeper to remove spyware
http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10405877.html
or
SpyBot S&D searches your harddisk for so-called spy- or adbots;
http://security.kolla.de/
or
Adaware
http://www.lavasoftusa.com/software/adaware/
3. If still no joy, download HijackThis
http://www.majorgeeks.com/download3155.html
Run the program and you will find many entries. Most are OK. Post the log at http://www.hijackthis.de/ and click Analyse, Save. Post a link to the saved list here.
1. If these trojans are in System Restore, antivirus programs cannot delete them. Disable and Enable System Restore
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
2. If no joy, antivirus programs are designed to remove virus, not mailware. You need mailware removers.
Ewido to remove trojans
http://www.ewido.net/en/
and
Spy Sweeper to remove spyware
http://www.download.com/Webroot-Spy-Sweeper/3000-8022_4-10405877.html
or
SpyBot S&D searches your harddisk for so-called spy- or adbots;
http://security.kolla.de/
or
Adaware
http://www.lavasoftusa.com/software/adaware/
3. If still no joy, download HijackThis
http://www.majorgeeks.com/download3155.html
Run the program and you will find many entries. Most are OK. Post the log at http://www.hijackthis.de/ and click Analyse, Save. Post a link to the saved list here.
ASKER
ASKER
here is the hijackthis log
Logfile of HijackThis v1.99.1
Scan saved at 10:52:38 AM, on 7/17/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon .exe
C:\WINNT\system32\services .exe
C:\WINNT\system32\lsass.ex e
C:\WINNT\System32\termsrv. exe
C:\WINNT\system32\svchost. exe
C:\WINNT\system32\spoolsv. exe
C:\WINNT\system32\drivers\ CDAC11BA.E XE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost. exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINNT\system32\CBA\pds. exe
C:\WINNT\System32\llssrv.e xe
C:\WINNT\System32\tcpsvcs. exe
C:\WINNT\System32\sfmprint .exe
c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.e xe
C:\WINNT\system32\MSTask.e xe
C:\WINNT\System32\snmp.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER .EXE
C:\WINNT\system32\stisvc.e xe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\Win Mgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost. exe
C:\WINNT\system32\Dfssvc.e xe
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\ inetinfo.e xe
C:\WINNT\System32\sfmsvc.e xe
C:\WINNT\System32\msdtc.ex e
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost. exe
C:\WINNT\system32\winlogon .exe
C:\WINNT\system32\rdpclip. exe
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\reals ched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee.com\VSO\mcvss hld.exe
c:\program files\mcafee.com\agent\mca gent.exe
c:\progra~1\mcafee.com\vso \mcvsescn. exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\system32\ctfmon.e xe
C:\DOCUME~1\ADMINI~1\APPLI C~1\FNTS~1 \fast.exe
C:\WINNT\system32\sistray. exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~1\mcafee.com\age nt\McDash. exe
c:\program files\mcafee.com\shared\mg html.exe
c:\PROGRA~1\mcafee.com\vso \mcmnhdlr. exe
C:\WINNT\explorer.exe
C:\WINNT\system32\logon.sc r
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\SYMANT~1\VPTra y.exe
C:\Program Files\Common Files\Real\Update_OB\reals ched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee.com\VSO\mcvss hld.exe
c:\progra~1\mcafee.com\vso \mcvsescn. exe
c:\program files\mcafee.com\agent\mca gent.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\system32\ctfmon.e xe
C:\DOCUME~1\ADMINI~1\APPLI C~1\FNTS~1 \fast.exe
C:\WINNT\system32\sistray. exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip3 2.exe
C:\Documents and Settings\Administrator\Loc al Settings\Temp\HijackThis.e xe
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Default_Sear ch_URL =
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\In ternet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://www.towergate.org/
R0 - HKLM\Software\Microsoft\In ternet Explorer\Search,SearchAssi stant = http://www.mrfindalot.com/search.asp?si=20065&k=
R0 - HKLM\Software\Microsoft\In ternet Explorer\Search,CustomizeS earch = http://www.mrfindalot.com/search.asp?si=20065&k=
R1 - HKCU\Software\Microsoft\In ternet Explorer\SearchURL,(Defaul t) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0 0A0C908246 7} - C:\WINNT\System32\msdxm.oc x
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0 090271D4F8 8} - C:\Program Files\Yahoo!\Companion\Ins talls\cpn0 \yt.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9 05236F6F65 5} - c:\progra~1\mcafee.com\vso \mcvsshl.d ll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroChec k.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra y.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals ched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe " -atboottime
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS O\mcmnhdlr .exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvss hld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl nt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age nt\mcagent .exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age nt\McUpdat e.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Wacinrka] C:\DOCUME~1\ADMINI~1\APPLI C~1\FNTS~1 \fast.exe
O4 - HKCU\..\Run: [Edrc] "C:\PROGRA~1\MANTEC~1\lsas s.exe" -vt ndrv
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB Update\qbu pdate.exe
O4 - Global Startup: Utility Tray.lnk = C:\WINNT\system32\sistray. exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH .HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3 \Office10\ EXCEL.EXE/ 3000
O16 - DPF: {17492023-C23A-453E-A040-C 7C580BBF70 0} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {266B9238-31A5-4B53-9039-2 72FE846DF9 D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab
O16 - DPF: {2B323CD9-50E3-11D3-9466-0 0A0C970049 8} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-F A1D4F56A2A B} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5 A1EDB1D8A2 1} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-D C1FA91D2FC 3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138403477671
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0 09027A35D7 3} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C 18E1ADA438 9} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
O16 - DPF: {E7D2588A-7FB5-47DC-8830-8 3260566100 9} - https://livewc02.custhelp.com/7520-b289h-turbotax/rnl/java/RntX.cab
O17 - HKLM\System\CCS\Services\T cpip\..\{0 5801ECE-E5 47-41EB-B2 CA-D1E53EC E437C}: NameServer = 166.82.1.3,166.82.1.8
O17 - HKLM\System\CS1\Services\T cpip\..\{0 5801ECE-E5 47-41EB-B2 CA-D1E53EC E437C}: NameServer = 166.82.1.3,166.82.1.8
O17 - HKLM\System\CS2\Services\T cpip\..\{0 5801ECE-E5 47-41EB-B2 CA-D1E53EC E437C}: NameServer = 166.82.1.3,166.82.1.8
O20 - AppInit_DLLs: C:\WINNT\system32\services .dll C:\WINNT\system32\nopdb.dl l
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon .dll
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\ CDAC11BA.E XE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin. exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\CBA\pds. exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso \mcshield. exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age nt\mctsksh d.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age nt\mcupdmg r.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Logfile of HijackThis v1.99.1
Scan saved at 10:52:38 AM, on 7/17/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon
C:\WINNT\system32\services
C:\WINNT\system32\lsass.ex
C:\WINNT\System32\termsrv.
C:\WINNT\system32\svchost.
C:\WINNT\system32\spoolsv.
C:\WINNT\system32\drivers\
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINNT\system32\CBA\pds.
C:\WINNT\System32\llssrv.e
C:\WINNT\System32\tcpsvcs.
C:\WINNT\System32\sfmprint
c:\PROGRA~1\mcafee.com\age
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\regsvc.e
C:\WINNT\system32\MSTask.e
C:\WINNT\System32\snmp.exe
C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\50\bin\OWSTIMER
C:\WINNT\system32\stisvc.e
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\Win
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.
C:\WINNT\system32\Dfssvc.e
C:\WINNT\System32\dns.exe
C:\WINNT\System32\inetsrv\
C:\WINNT\System32\sfmsvc.e
C:\WINNT\System32\msdtc.ex
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINNT\System32\svchost.
C:\WINNT\system32\winlogon
C:\WINNT\system32\rdpclip.
C:\WINNT\SOUNDMAN.EXE
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee.com\VSO\mcvss
c:\program files\mcafee.com\agent\mca
c:\progra~1\mcafee.com\vso
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\system32\ctfmon.e
C:\DOCUME~1\ADMINI~1\APPLI
C:\WINNT\system32\sistray.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\PROGRA~1\mcafee.com\age
c:\program files\mcafee.com\shared\mg
c:\PROGRA~1\mcafee.com\vso
C:\WINNT\explorer.exe
C:\WINNT\system32\logon.sc
C:\WINNT\Explorer.EXE
C:\WINNT\SOUNDMAN.EXE
C:\PROGRA~1\SYMANT~1\VPTra
C:\Program Files\Common Files\Real\Update_OB\reals
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\McAfee.com\VSO\mcvss
c:\progra~1\mcafee.com\vso
c:\program files\mcafee.com\agent\mca
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINNT\system32\ctfmon.e
C:\DOCUME~1\ADMINI~1\APPLI
C:\WINNT\system32\sistray.
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\WINZIP\winzip3
C:\Documents and Settings\Administrator\Loc
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-9
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroChec
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTra
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\reals
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VS
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvss
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oascl
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\age
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Wacinrka] C:\DOCUME~1\ADMINI~1\APPLI
O4 - HKCU\..\Run: [Edrc] "C:\PROGRA~1\MANTEC~1\lsas
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QB
O4 - Global Startup: Utility Tray.lnk = C:\WINNT\system32\sistray.
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
O16 - DPF: {17492023-C23A-453E-A040-C
O16 - DPF: {266B9238-31A5-4B53-9039-2
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {30528230-99F7-4BB4-88D8-F
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
O16 - DPF: {6E32070A-766D-4EE6-879C-D
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C
O16 - DPF: {E7D2588A-7FB5-47DC-8830-8
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS2\Services\T
O20 - AppInit_DLLs: C:\WINNT\system32\services
O20 - Winlogon Notify: NavLogon - C:\WINNT\system32\NavLogon
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Intel PDS - Intel® Corporation - C:\WINNT\system32\CBA\pds.
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\age
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Age
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
my ip address begins with a 166.82 does that mean that those are probably legit?
Yes, those IP address are probably legit.
ASKER
well i ran hjt and fixed the two issues you told me to but mcafee is still detecting viruses.
Check if McAfee is giving you a false positive. Use another online service to check for virus
Housecall Online Scan
http://housecall.antivirus.com
or
Panda Activescan
http://www.pandasoftware.com/products/activescan.htm
or
Kaspersky Virus Scan
http://www.kaspersky.com/virusscanner
Housecall Online Scan
http://housecall.antivirus.com
or
Panda Activescan
http://www.pandasoftware.com/products/activescan.htm
or
Kaspersky Virus Scan
http://www.kaspersky.com/virusscanner
ASKER
well I've downloaded, spysweeper, adaware, advanced spyware remover, spybot SD, and Ewido and almost all of them are detecting things that i can't get rid of.
danielwebb,
Did you disable and re-enable System Restore? Sometimes mailware are hidden there.
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
Did you disable and re-enable System Restore? Sometimes mailware are hidden there.
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDocument&src=sec_doc_nam
ASKER
that document only talks about doing that on xp I'm running 2000 server
Danielwebb,
Sorry! Windows 2000 does not have System Restore. You may have a rootkit. Here is how to detect and remove it
Rootkit Revealer
http://www.sysinternals.com/Utilities/RootkitRevealer.html
or
F-Secure Blacklight
http://www.f-secure.com/blacklight/try.shtml
Sorry! Windows 2000 does not have System Restore. You may have a rootkit. Here is how to detect and remove it
Rootkit Revealer
http://www.sysinternals.com/Utilities/RootkitRevealer.html
or
F-Secure Blacklight
http://www.f-secure.com/blacklight/try.shtml
Here is how to remove SurfSideKick 3
http://www.bleepingcomputer.com/forums/topic9549.html
If you have difficulty with the HijackThis log, Post the log at http://www.hijackthis.de/ and click Analyse, Save. Post a link to the saved list here.
Best wishes!