Hi
Two days before while surfing the internet, suddenly a Pes Trap software dislodged itself inmy trayicon and then started scanning everything. I found it, exited frm there and removed the program from the control panel. Then went to the CCleaner and analyzed and cleaned everything. Byt hen my Symantec antivirus ,was screaming---computer is infected and use antispyware tools with a "red sphere with a cross on it" icon.
I ran the anti virus and found winstall.exe tried to quarantine or delete couldnt....
I ran the adaware and whatever I found I have attached below and it is quarantined on my computer right now.
ArchiveData(auto-quarantine- 2006-07-23 21-28-44.bckp)
Referencefile : SE1R115 18.07.2006
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\06 14 06 dsh2 RF 700MHz 0.5Wkg nocodazole hunb.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\Vidya\recent\Desktop.ini
obj[2]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\06 29 06 dsh1 Sham w-conotoxin 2uM.LNK
obj[3]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[4]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\mediaplayer\medialibraryui mllastselectednode
obj[5]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\mediaplayer\player\settings opendir
obj[6]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\mediaplayer\preferences lastplaylistindex
obj[7]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\mediaplayer\preferences lastplaylist
obj[8]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\clip organizer\search\last query
obj[9]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\common\general symbolmru
obj[10]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\common\open find\microsoft powerpoint\settings\save as\file name mru value
obj[11]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\common\open find\microsoft word\settings\open\file name mru value
obj[12]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\common\open find\microsoft word\settings\save as\file name mru value
obj[13]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\excel\recent files
obj[14]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\powerpoint\recent file list
obj[15]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\powerpoint\recent templates
obj[16]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\powerpoint\recent typeface list
obj[17]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\powerpoint\recentfolderlist
obj[18]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\office\10.0\powerpoint\recenttemplatelist
obj[19]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\windows\currentversion\applets\regedit lastkey
obj[20]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\windows\currentversion\explorer\runmru
obj[21]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\HUNB cells.LNK
obj[22]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Igor pre-ONR 2003.LNK
obj[23]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\index.dat
obj[24]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\JIF-Radiation.LNK
obj[25]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\KTW37T6A.LNK
obj[26]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Lab Presentation For BPS.LNK
obj[27]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Library.LNK
obj[28]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\MERS Southeast Legal Seminar (11[1].10.04) final.LNK
obj[29]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\MSD.LNK
obj[30]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\My Documents.LNK
obj[31]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Normal.LNK
obj[32]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\NOtes of P19 work in 2006.LNK
obj[33]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Notes on HUNB RF Vial 5 work 2006.LNK
obj[34]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Notes on HUNB RF WORK Vial 5 work 2006.LNK
obj[35]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\NOtes_on_RF_data_from_2005_vials3_4_5.LNK
obj[36]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\OXIJKTMV.LNK
obj[37]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\P19 and HUNB RF Label and Cascades.LNK
obj[38]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\P19 cells.LNK
obj[39]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\P19 pathways.LNK
obj[40]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\LastLoginTime
obj[41]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Possible interests.LNK
obj[42]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Presentation1.LNK
obj[43]=MRU FileReference : C:\Documents and Settings\Vidya\Application Data\microsoft\office\recent\Presentation3.LNK
obj[44]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips1
obj[45]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips2
obj[46]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips3
obj[47]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips4
obj[48]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips5
obj[49]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips6
obj[50]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips7
obj[51]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentClips8
obj[52]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentSkins2
obj[53]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentSkins3
obj[54]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\realnetworks\realplayer\6.0\preferences\MostRecentSkins4
obj[74]=MRU RegReference : .DEFAULT\software\microsoft\windows media\wmsdk\general computername
obj[75]=MRU RegReference : S-1-5-18\software\microsoft\windows media\wmsdk\general computername
obj[76]=MRU RegReference : S-1-5-21-2996401450-3968480119-282924165-1006\software\microsoft\windows media\wmsdk\general computername
SPYWARENO
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
[b]obj[26]=Process : C:\winstall.exe
obj[29]=RegKey : software\sno2
obj[30]=RegValue : software\microsoft\windows\currentversion\policies\system "Wallpaper"
obj[31]=RegValue : software\microsoft\internet explorer\desktop\general "WallpaperFileTime"
obj[32]=RegData : software\microsoft\internet explorer\desktop\general "WallpaperStyle"
obj[33]=RegData : control panel\desktop "WallpaperStyle"
obj[34]=RegData : software\microsoft\windows\currentversion\policies\explorer "ClassicShell"
obj[35]=RegData : software\microsoft\windows\currentversion\policies\explorer "ForceActiveDesktopOn"
obj[36]=RegData : software\microsoft\windows\currentversion\policies\explorer "NoActiveDesktop"
obj[37]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoAddingComponents"
obj[38]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoChangingWallpaper"
obj[39]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoComponents"
obj[40]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoEditingComponents"
obj[41]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoHTMLWallPaper"
obj[42]=RegData : software\microsoft\internet explorer\desktop\general "ComponentsPositioned"
obj[43]=Folder : C:\Program Files\PestTrap
obj[44]=File : C:\nj.exe
obj[45]=File : C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP83\A0012349.exe
obj[46]=File : C:\Documents and Settings\Vidya\Application Data\Install.dat
TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[27]=IECache Entry : Cookie:vidya@atdmt.com/
obj[28]=IECache Entry : Cookie:vidya@2o7.net/
OTHER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[47]=File : C:\WINDOWS\prefetch\NJ.EXE-292BD401.pf
The line on the winstall.exe and the nj.exe had turned up two days before I ran the adaware and ran the anti virus scan on two separate locations.
Then i backed up everything and tried to run the system restore to a previous system point, it said the restoratiion was incomplete and I tried with different system points with the same result..
So, I went to my school system supports, they started the computer in safe mode and ran the spybot and cleaned the active desktop which came up and then they ran the antivirus scann again, I got two files upn there which said they dont exist on search. SO they said my computer is safe.
BUt now after two days, I ran the Adaware again and found hte following:
ArchiveData(spyware.bckp)
Referencefile : SE1R115 18.07.2006
======================================================
SPYWARENO
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=File : C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP83\A0012407.exe
obj[1]=RegValue : software\microsoft\internet explorer\desktop\general "WallpaperLocalFileTime"
obj[2]=RegData : software\microsoft\internet explorer\desktop\general "WallpaperStyle"
obj[3]=RegData : control panel\desktop "WallpaperStyle"
obj[4]=RegData : software\microsoft\windows\currentversion\policies\explorer "ClassicShell"
obj[5]=RegData : software\microsoft\windows\currentversion\policies\explorer "NoActiveDesktop"
obj[6]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoAddingComponents"
obj[7]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoChangingWallpaper"
obj[8]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoComponents"
obj[9]=RegData : software\microsoft\windows\currentversion\policies\activedesktop "NoEditingComponents"
The first system volume information file turned up on the anti virus scan too but cannot find it anywhere in the system.
I looked up other stuff on google and found that my desktop might have frozen and other things will follow. SO I tried changing it, I can now change the color but cannot upload a desktop background in terms of a picture. Also I cannot a system restore in normal or safe mode.
I ran the panda scan software, it found some malicious cookies, I deleted those, but that didnt help.What do I do? PLease help thanks!
