Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Dropper.Delf.3.L + SdBot Cant get rid of it
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Dropper.Delf.3.L + SdBot Cant get rid of it  
Forum Quick Jump
 
New Topic Post reply to : Dropper.Delf.3.L + SdBot Cant get rid of it Printable version of : Dropper.Delf.3.L + SdBot Cant get rid of it
[ << Previous Thread | Next Thread >> ]

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-8-2004 8:32 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
I recently had a major problem with the SdBot virus. i remastered my system and found that it did not remove the trojan or virus but i managed to download ZoneAlarm. Whihc seems to have kept it quiet. I am not sure if it is still there. I possibly is. But for some reason i have now just recieved th Dropper.Delf.3.L in my temp folder. AVG cannot detect or delete. Here is my HijackThis log
 
Logfile of HijackThis v1.97.7
Scan saved at 19:35:01, on 08/11/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\POWERPNT.EXE
C:\Program Files\Maintanance + Tools\BitComet\BitComet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows AdTools\WinAdTools.exe
C:\Program Files\BullsEye Network\bin\bargains.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\Windows AdTools\WinRatchet.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\Program Files\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.co.uk/center
O2 - BHO: (no name) - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows AdTools] C:\Program Files\Windows AdTools\WinAdTools.exe
O4 - HKLM\..\Run: [salm] c:\temp\salm.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\Run: [BullsEye Network] C:\Program Files\BullsEye Network\bin\bargains.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKLM\..\RunOnce: [djtopr1150.exe] "C:\DOCUME~1\Andrew\LOCALS~1\Temp\djtopr1150.exe"
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: Packard Bell (HKLM)
O9 - Extra button: Research (HKLM)
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.co.uk/center
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=9247fa4b774fc858a0d12810e56cbac556372bbce609d43ef61e47269db11fafb4025e857f9a0dbf1cf295cd3e530080bac1cef68b8c1c3448468b320ab3336088:9210ca0a5a6a24553e33577254537a6f
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099666378263
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C1EAE84-0BDA-4AC2-B15F-5A8886964621}: NameServer = 80.225.252.58 80.225.252.50
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14290
 
   Posted 11-9-2004 11:18 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Hey cool
You have more problems than Sdbotsmhair
Run this scanner – mwav exe : http://home9.inet.tele.dk/le01/Sikkerhed.htm

Activate all, in settings- Scan

Download Spybot Search and Destroy here : http://www.safer-networking.org/index.php?page=mirrors if it is not already installed on your computer
Install the program and then start it. Once the program has started make sure you are in the Spybot-S&D section. Click on the "Search for Updates" button. Download all updates. In some cases the program will restart after an update. When updated, click on the Immunize "Scan System" button. When the Check is over, fix all marked with red
 
 

Open adaware and Click the "Check for updates now" line on the main screen. Click the "Connect" button on the webupdate screen.

If an update is available download it and install it. Click the "Finish" button to go back to the main screen.

Click on the Settings button (gear symbol in the upper right corner of the main status screen) in the quick launch toolbar to open the General settings screen. Check the "Automatically quarantine objects prior to removal" setting and then click "Proceed" to save your changes

Click the "Scan now" button in the main menu on the left side of the main status screen or use the "Start" button in lower right corner. This will open the Preparing System Scan screen. Please deselect "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat. Then select "Use custom scanning options" and click "Customize". This will open the Scan Settings Page. Make sure all of the following are On with a "green" checkmark:

Scan within archives
Scan active processes
Scan Registry
Deep-scan Registry
Scan my IE Favorites for banned URLs
Scan my Hosts File

Then Click the Advanced Button on the left side to open the Advanced Settings screen. Make sure the following is on with a "green" checkmark:

Others are optional to be checked or unchecked.

Then click on the "Tweak" Button to open up the tweak settings.

Open up the Scanning Engine section and make sure ll of the following are On with a "green" checkmark:

Scan registry for all users instead of current user only

Make sure the following is unchecked with a "red" X:

Unload recognized processes & modules during scan.

Open up the Cleaning Engine section and make sure all of the following are On with a "green" checkmark:

Always try to unload modules before deletion
During Removal, unload Explorer and IE if necessary
Let Windows remove files in use at next reboot.

Click the "Proceed" button to save settings.

Click the "Next" button to start the scan.

When a scan is completed the Performing System Scan screen will change name to "Scan Complete".

Click the "Next" button to get to the Scanning Results screens where more information about the objects detected during the scan is available.


To fix all the bad critical objects do the following:

Right click on one of them to open up the selection screen. Click the "Select All" button to select all entries.

When all are selected Click "Next" and then "OK" in the pop-up window to confirm the removal.

Plug-Ins for Ad-Aware (VX2 Cleaner)
Download the free VX2 Cleaner here : http://download.lavasoft.de.edgesuite.n...leaner.exe

Close Ad-Aware SE build 1.04 and Ad-Watch (if running)
Install the VX2 Cleaner
Start Ad-Aware SE build 1.04
Go to “Plug-ins”
Select the VX2 Cleaner plug-in and click “Run Plugin”
If your computer isn’t infected, click “Close”.

If your computer is infected:

Select “Clean System”
Reboot your computer
Scan your computer with Ad-Aware
Remove any VX2 objects detected
Reboot your computer again
Run a second scan to make sure the files have been removed from your computer



Cwshredder:
http://www.spywareinfo.com/~merijn/downloads.html
Or: http://www.softpedia.com/public/cat/10/17/10-17-150.shtml
 Unzip to own folder,check for updates if needed, close all other windows-Fix
Please update Hijackthis, or download a new version: :  http://danborg.org/spy/HJT/hijackthis.exe
Check for updates for Windows and Internet Explorer . Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/



Post new log




Touch
Back to Top
 

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-9-2004 7:38 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
This came up on the first scanning tool you gave me.
File C:\WINDOWS\RESTORE.INS tagged as not-a-virus:NetTool.PsKill. No Action Taken.
File C:\WINDOWS\System32\exdl.exe tagged as not-a-virus:AdWare.BargainBuddy.j. No Action Taken.
File C:\WINDOWS\System32\exul.exe tagged as not-a-virus:RiskWare.PSWTool.EDialer. No Action Taken.
File C:\WINDOWS\System32\msbe.dll tagged as not-a-virus:AdWare.BargainBuddy.l. No Action Taken.
the second scanning tool was downloaded. it was unzipped in winrar and was in another language. winrar came up with virus errors!!!!!!!?? so i didnt run that or pursue it???
Spybot ran succesfully and removed many items successfully
On adaware, when i go to update it gets to 5% and stops downloading. i did not mnaage to update however i did scan with settings you told me and managed to remove a few items.
Spy Subtract found alot of problems of which i delted all(Great program)
Updated Hijackthis log
Logfile of HijackThis v1.98.2
Scan saved at 18:38:46, on 09/11/2004
Platform: Windows XP  (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
c:\Program Files\interMute\SpySubtract\SpySub.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\hijackthis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.co.uk/center
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.co.uk/center
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=9247fa4b774fc858a0d12810e56cbac556372bbce609d43ef61e47269db11fafb4025e857f9a0dbf1cf295cd3e530080bac1cef68b8c1c3448468b320ab3336088:9210ca0a5a6a24553e33577254537a6f
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099666378263
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C1EAE84-0BDA-4AC2-B15F-5A8886964621}: NameServer = 80.225.252.58 80.225.252.50


Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14290
 
   Posted 11-10-2004 7:04 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Anyway, when you have fixed this:
You have a clean log;-)
Check for updates for Windows and Internet Explorer . Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/
 
Still have problems?


Touch
Back to Top
 

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-10-2004 12:02 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
I dont think i have anymore problems. i think you have destroyed it all for mejumpin
 
THANKYOU VERY MUCH
 
So are you saying when i have removed that checked item from hijackthis i will have a clean bill of health?
 
thanks very much for your help.
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14290
 
   Posted 11-10-2004 12:13 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Yes, you are cleansmilewinkgrin
 
Install these for safer surfing:
Check for updates for Windows and Internet Explorer every week or so. Download each critical update one by one, rebooting when necessary.. Repeat this until you get the message "no critical updates available"

http://windowsupdate.microsoft.com/
 
I am glad i could help;-)


Touch
Back to Top
 

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-10-2004 4:50 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Honeslty cant thank you enough you are the DON.
This is the clean log hopefully
Thought id never get rid of it. CHEERS AGAINsmile
 
Logfile of HijackThis v1.98.2
Scan saved at 15:46:34, on 10/11/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgwb.dat
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Maintanance + Tools\BitComet\BitComet.exe
C:\PROGRA~1\Grisoft\AVG7\avginet.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.packardbell.co.uk/center
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=runonce&pver=6.0&plcid=0x0809
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe"  -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Packard Bell - {1D49B7D4-524D-4ac9-BC34-B4822CAE4BB1} - C:\Apps\IECustom\script.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=www.packardbell.co.uk/center
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1099666378263
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5C1EAE84-0BDA-4AC2-B15F-5A8886964621}: NameServer = 80.225.252.58 80.225.252.50
 
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14290
 
   Posted 11-10-2004 5:42 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Clean - Donesmilewinkgrin


Touch
Back to Top
 

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-18-2004 2:58 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Unfortunately I have recieved the same viruses again. I am doing all that you have described again after having to remaster the system as it would not let me boot up normally.
 
I am doing all the scans as before but i am wondering why it has returned and how can i stop them from coming back.
 
Thanks again
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14290
 
   Posted 11-18-2004 3:07 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
They can be in restore points.
Disable System Restore, to flush them
 
Reboot enable system restore again


Touch
Back to Top
 

Spiffy.Helper
New Member


Date Joined Nov 2004
Total Posts : 26
 
   Posted 11-29-2004 2:47 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
Dropper.Delf.3L reinstalls itself VIA ActiveX control. Please follow these
steps to uninstall it.
1) Turn System Restore OFF
2) Open IE -> Tools -> Internet Options -> Settings -> View Objects
Delete a control called 'Illuminatus 4.5' and another called something like:
{575FJ-567F5H-5IFJK5}. Pleae note that I'm not sure which if the two
deletes the virus but it is one of the two for sure.
3) Run a full virus scan
4) If your software has detected no viruses turn System Restore ON
I hope this has helped. Please NOTE: This is only if the virus has been
installed VIA an ActiveX control although it might work for other ways.
Back to Top
 

AceSpurs
New Member


Date Joined Nov 2004
Total Posts : 11
 
   Posted 11-29-2004 5:39 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
thnakyou they have gone
Back to Top
 

Spiffy.Helper
New Member


Date Joined Nov 2004
Total Posts : 26
 
   Posted 12-1-2004 10:04 (GMT +1)    Quote: Dropper.Delf.3.L + SdBot Cant get rid of itAlert an admin about: Dropper.Delf.3.L + SdBot Cant get rid of it
No problem! Glad to help you!
(Im getting sick of this virus, Encountered it 3 times since my first experience with it).
Back to Top
 
New Topic Post reply to : Dropper.Delf.3.L + SdBot Cant get rid of it Printable version of : Dropper.Delf.3.L + SdBot Cant get rid of it
 
Forum Information
Currently it is Tuesday, January 06, 2009 1:43 PM (GMT +1)
There are a total of 65.861 posts in 16.164 threads.
In the last 3 days there were 22 new threads and 85 reply posts. View Active Threads
Who's Online
This forum has 27758 registered members. Please welcome our newest member, Nards.
48 Guest(s), 1 Registered Member(s) are currently online.  Details
Geekguy
5 Latest Threads
Have I a machine infection? (8)06-01-2009 12:42:25 (Geekguy)
How to restore missing control panel and properties (0)06-01-2009 12:30:09 (Nards)
Google Redirect Virus - Stubborn Version!!! (11)06-01-2009 12:24:11 (DaveWales)
Please help with my Hijackthis log (6)06-01-2009 12:13:33 (iwanttofly4)
Trouble accessing ColdFusion pages!? (3)06-01-2009 10:35:35 (Alin Vlad)