Hi Cheryl,
Run an updated Spybot Search and Destroy ( http://security.kolla.de/ ) and fix all items in RED and reboot. Then after closing all browser windows, fix the items listed below that are remaining using HijackThis and then reboot again.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxycfg.marketscore.com/gencfg.asp?id1=xknnMYGXNh5&id2=U170btwUq5f&lp=1&nsv=5.0.0.7
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Companion BHO - {13F537F0-AF09-11d6-9029-0002B31F9E59} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMMON\YCOMP5,0,2,0.DLL (file missing)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst.cab
----------------
Tom41 wrote:
There's just 1 registry entry...
Click Start > Run > type msconfig and click OK.
Click the startup tab and uncheck the entry for C:\Windows\windrive.exe. Click apply/ok and reboot.
Delete windrive.exe.
**This is a password stealing trojan, so change all passwords.
Did you do what Tom suggested? You still have the entry
O4 - HKLM\..\Run: [Drivers] C:\WINDOWS\WinDrive.exe
Trojan “Backdoor.Nibu” See http://www.symantec.com/avcenter/venc/data/backdoor.nibu.html
After following Tom’s instruction, you could also remove the remaining files by using Symantec’s removal instructions.
In addition:
You could also try to remove it using an Anti-Trojan Program. (Since you’re worried about 30-day programs, remove it after you’re done) I recommend either Trojanhunter or TDS-3 (both have thirty day trials). Generally, Anti-Virus programs do have some Trojan detection/removal but they are not in the Anti-Trojan business so it is a good idea to use an Anti-Trojan program.
You really should install an Anti-Virus program. Since you don’t have an Anti-Virus program you could also use the following online AV scanners (in addition to the one you already used)
- Panda ActiveScan http://www.pandasoftware.es/activescan/activescan-com.asp
- Trend Micro Housecall http://housecall.antivirus.com/
Recommend Panda ActiveScan first, Trend HouseCall second, as the two best online scans, in that order.
----------------------
Do not fix this with HijackThis you may lose your internet connection.
O10 - Broken Internet access because of LSP provider 'csloa.dll' missing
‘csloa.dll’ was a file that was installed with the Marketscore. The ‘csloa.dll’ file is loaded by NSCHECK.exe. But since NSCHECK.exe loads from the startup group and is not in your HijackThis logfile it must have already been removed.
If Spybot S&D did not correct this entry (as Spybot S&D does remove Marketscore) What I'd do is download and run LSP-Fix available from http://www.cexx.org/lspfix.htm, it does a good job of fixing corrupted LSP stacks.
---------------------
Now back to Spyware, for the future see: So how did I get infected in the first place? http://www.net-integration.net/cgi-bin/forum/ikonboard.cgi?;act=ST;f=38;t=3051
Four of the most recommended anti-spyware programs are SpywareBlaster and SpywareGuard and Spybot S&D and Ad-aware. If you install all four programs, keep them updated, and scan with Spybot S&D and Ad-aware periodically, you will be fairly well-protected from spyware.
Thought I would mention that SpywareGuard includes a browser hijack stopper (Javacool calls it Browser Hijack Blaster) that protects your system from browser hijackers and spyware that alters your Internet Explorer settings.
Good Luck!