The file name was just numbers, it was 49674074977093.exe.

Microsoft Windows Script Host Version 5.6

Then right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties.

This will ensure your computer always has the latest security updates.

IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll O4 - HKLM\..\Run: Press the CleanUp! C:\Documents and Settings\rww\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned. check it out I manually deleted the file, and found no traces of it using Ewido, Spy Sweeper, or Mcafee.

C:\Documents and Settings\rww\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned. To resolve this, restart the computer and try again.Ensure that the Safe Mode option is selected.Press Enter. Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! That’s the difference between having to wait hours for a virus signature that detects a new threat or just minutes.

  In addition, the malware collects information about the OS and system settings, as well as the list of the encrypted files; it then attempts to send these data to a remote
  Untick - Show hidden files and folder Tick - Hide file extensions for known types Tick - Hide protected operating system files Click Yes to confirm & then click OK
  Please start AVG Anti-Spyware and run a full scan.Click on Scanner on the toolbar.Click on the Settings tab.Under How to act?Click on Recommended Action and choose Quarantine from the popup menu.
  4. Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context

Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dllO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocxO3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dllO4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exeO4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Microsoft Windows Script Host Version 5.6 Random Runs removed from HKLM ... Edited by Shaba, 12 October 2006 - 11:46 AM. 0 #3 hydromon Posted 12 October 2006 - 04:05 PM hydromon New Member Topic Starter Member 9 posts Hello Shaba: I could Directory of C:\WINDOWS\system32 »»»»» Misc files. »»»»» Checking for older varients covered by the Rem3 tool.

Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dllO9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dllO9 - Extra 'Tools' menuitem: Yahoo! weblink Now click on Scan Settings In the scan settings make sure that the following are selected: o Scan using the following Anti-Virus database: + Extended (If available otherwise Standard) o Scan Valitun tekstin lainaus 18.10.2009 #1 iidu Rekisteröitynyt: 18.10.2009 Viestejä: 2 Apuva! If it had provided the location, we may have it removed via manual Registry editing.

C:\Documents and Settings\rww\Cookies\[email protected][1].txt -> TrackingCookie.Bridgetrack : Cleaned. Close HijackThis, and click OK to proceed. SSD drive disappearing Computer Won't Boot Safe Mode From Boot Menu Wont... navigate here spyaxe uninstaller NOT present ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Existing Pre-run Files ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~

This attachment comes with a Trojan Downloader, usually from the Family detected by ESET as JS/TrojanDownloader.Nemucod, among other variants.

Now click on the Save as Text button Save the file to your desktop.

CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more.

PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED.

Don't let the cybercriminals infect your system just because you forgot to install the most recent updates. When your system reboots, follow the prompts.

A tutorial on installing & using this product can be found here SPYWAREBLASTER SpywareBlaster prevents the installation of malicious ActiveX, adware, browser hijackers, dialers, and other potentially unwanted software. Right-click on the list and choose Select All