Run the installer. When installing uncheck: Install background guard Install scan via context menu Now open Ewido. Update the definitons for Ewido. Now close Ewido for right now.
Please download and install Ad-Aware SE Personal from this page.
Now download and install the VX2 Cleaner from this page.
Run Ad-Aware SE Personal. Click Add-Ons. Double-click VX2 Cleaner. Click Ok to Excute this tool. If nothing is found click Ok and exit the program.
or
If malware is found click Clean System. When it's done click Start in Ad-Aware SE Personal. Make sure Perform smart system scan is checked. Click Next. Let it clean anything it finds.
Go to Add/Remove programs and remove(uninstall) the following, if present:
EBates MoeMoney
The above could appear anywhere within the entry. Be careful not to remove any personal or system software.
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\WINDOWS\system32\qbohfup.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\enhtb.dll
C:\WINDOWS\dsr.dll
C:\WINDOWS\satmat.exe
C:\WINDOWS\enhupdt.exe
C:\WINDOWS\dinst.exe
Search for...
DLHelperEXE.exe
...using "Start | Search...".
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".
Now reboot.
Run Ewido. Click on scanner. (Don't do anything on the computer while Ewido is running.) Click Complete System Scan. If you get a prompt asking to clean files then click OK. When it cleans the first file put a check by Perform action on all infections and then choose clean and click OK. Once the scan is done choose Save Report and save it your desktop. Close Ewido.
Run Ad-Aware SE Personal. Click Start in Ad-Aware SE Personal. Make sure Perform smart system scan is checked. Click Next. Let it clean anything it finds.
Now reboot and post a new HijackThis log along with the Ewido log.
ALgal
1.2K Posts
0
September 8th, 2005 10:00
Hello and Welcome Scottnheidi,
You have a Nail and/or Epolvy infection.
Please download Ewido Security Suite.
Run the installer.
When installing uncheck:
Install background guard
Install scan via context menu
Now open Ewido.
Update the definitons for Ewido.
Now close Ewido for right now.
Please download and install Ad-Aware SE Personal from this page.
Now download and install the VX2 Cleaner from this page.
Run Ad-Aware SE Personal.
Click Add-Ons.
Double-click VX2 Cleaner.
Click Ok to Excute this tool.
If nothing is found click Ok and exit the program.
or
If malware is found click Clean System.
When it's done click Start in Ad-Aware SE Personal.
Make sure Perform smart system scan is checked.
Click Next.
Let it clean anything it finds.
Go to Add/Remove programs and remove(uninstall) the following, if present:
EBates MoeMoney
The above could appear anywhere within the entry. Be careful not to remove any personal or system software.
Run HiJackThis and click "Scan", then check(tick) the following, if present:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {0007522A-2297-43C1-8EB1-C90B0FF20DA5} - C:\WINDOWS\enhtb.dll
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll
O2 - BHO: (no name) - {432D8C41-8586-11D8-997D-00C026232EB9} - C:\WINDOWS\bvm202.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: (no name) - {EA5A82FB-D6BE-44F9-9363-B1ABABC153C1} - (no file)
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Enh Win Updt] C:\WINDOWS\enhupdt.exe
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [maxpdzp] C:\WINDOWS\system32\qbohfup.exe r
O4 - Startup: DLHelperEXE.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (HKCU)
O16 - DPF: {AED98630-0251-4E83-917D-43A23D66D507} (WebHandler Class) - http://activex.microgaming.com/DLhelper/version7/dlhelper.cab
Now, with all windows closed except HiJackThis, click "Fix checked".
How to see hidden files in Windows.
Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:
files...
C:\WINDOWS\system32\qbohfup.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\enhtb.dll
C:\WINDOWS\dsr.dll
C:\WINDOWS\satmat.exe
C:\WINDOWS\enhupdt.exe
C:\WINDOWS\dinst.exe
Search for...
DLHelperEXE.exe
...using "Start | Search...".
-
Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them from "Safe Mode".
Now reboot.
Run Ewido.
Click on scanner. (Don't do anything on the computer while Ewido is running.)
Click Complete System Scan.
If you get a prompt asking to clean files then click OK.
When it cleans the first file put a check by Perform action on all infections and then choose clean and click OK.
Once the scan is done choose Save Report and save it your desktop.
Close Ewido.
Run Ad-Aware SE Personal.
Click Start in Ad-Aware SE Personal.
Make sure Perform smart system scan is checked.
Click Next.
Let it clean anything it finds.
Now reboot and post a new HijackThis log along with the Ewido log.