Fresh HijackThis log...

CharlieBrown007CharlieBrown007 Northern Ireland
edited April 2008 in Spyware & Virus Removal
Hi there,

Thanks for the help here. I followed your instructions & successfully removed all the files you listed in the HijackThis log.

I then proceeded to your next set of instructions to unhide files, folders & protected operating system files.

There was no MyWay listed under Add or Remove Programs.

I removed the following files/folders:
  • Folder:
    • C:\Program Files\myway
  • Files:
    • C:\WINDOWS\system32\eshopperuninstall.exe
    • C:\WINDOWS\system32\uzxdmebxy.exe
    • C:\WINDOWS\system32\2scenicwu.exe
    • C:\WINDOWS\system32\scenicms.exe
Alongside uzxdmebxy.exe in C:\WINDOWS\system32, the following seemingly associated files where listed:
  • C:\WINDOWS\system32\uzxdmebxy.dat
  • C:\WINDOWS\system32\uzxdmebxy_nav.dat
  • C:\WINDOWS\system32\uzxdmebxy_navps.dat
The following files were not listed:
  • C:\WINDOWS\downloaded program files\egauth.inf
  • C:\WINDOWS\downloaded program files\sysnetsvc32.inf
I then proceeded to perform a fresh HijackThis log following the instructions given here.

I noticed in the new ActiveScan.txt file that uzxdmebxy.exe has re-instated itself in C:\WINDOWS\system32 and sysnetsvc32.inf is shown to be found in c:\windows\downloaded program files. I double checked both and uzxdmebxy.exe is back where ActiveScan says it is, but there is no sign of sysnetsvc32.inf still.

In the Kapersky log file, all files and folders within C:\Documents and Settings\Julie\Desktop\Interface\AddOns are still locked and cannot be deleted. It also lists 5 viruses found with 14 infected objects.

Everything that I removed from the previous HijackThis log was not listed on this fresh scan.

Here are the following fresh log files for you to look over, and once again thanks for the help you've given so far.

Comments

This discussion has been closed.