Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I am getting destroyed by this iworm_attck virus. I can't get rid of it no matter what I do. Can anyone help me remove it once and for all?

We will need to download some tools.
Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ We will need it later in safe modeDownload Ewido Security Suite then set it up this way Ewido Setup Instructions We will need this later in safe mode
Download killbox to your desktop from this link Killbox We will need it later in safe mode
Run this free online scan from Kaspersky http://kaspersky.com/kos/english/kavwebscan.html
Click Accept
When the updates are finished downloading, click Next, Scan Settings
Under Scan using the following antivirus database:, select extended
Make sure the Scan Archives and Scan Mail Bases options are selected as well. Click OK
Click My Computer and wait for the scan to finish
Click Save Report As. Under Save as type:, select Text file. Save this log to your Desktop and post a copy of it here.Next follow these directions to reboot into safe mode Safe Mode
Run Ewido from safe mode and let it delete all that it finds. When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop.
Run ATF-Cleaner from safe mode. Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.Reboot into nornmal mode.
Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.
Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.
Post the Kaspersky, Ewido and Hijack This logs.

I olsow suffer under this thing called iworm... I followed the guidelines above and here you have my log. kaspersky, ewido and hijack
---------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, June 12, 2006 8:12:09 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 12/06/2006
Kaspersky Anti-Virus database records: 199999
---------------------Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: trueScan Target - My Computer:
A:\
C:\
E:\
F:\
G:\
H:\
I:\Scan Statistics:
Total number of scanned objects: 141428
Number of viruses found: 12
Number of infected objects: 25
Number of suspicious objects: 0
Duration of the scan process: 02:37:14Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Thomas D\Local Settings\Application Data\Mozilla\Firefox\Profiles\bk7ef.default\Cache\F498AD79d01 Infected: not-a-virus:Porn-Dialer.Win32.PluginAccess.gen skipped
F:\Program Files\BearShare\Installer\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.bo skipped
F:\Program Files\BearShare\Installer\BSINSTALL.exe WiseSFX: infected - 1 skipped
F:\Program Files\BearShare\Installer\BSINSTALL.exe WiseSFX Dropper: infected - 1 skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0021.BIN Infected: not-a-virus:AdWare.Win32.F1Organizer.l skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0022.BIN Infected: not-a-virus:AdWare.Win32.IPInsight.a skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0023.BIN/data0002 Infected: not-a-virus:AdWare.Win32.FlashTrack.d skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0023.BIN Infected: not-a-virus:AdWare.Win32.FlashTrack.d skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0025.BIN/data0008 Infected: not-a-virus:AdWare.Win32.CommonName.k skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0025.BIN/data0009 Infected: not-a-virus:AdWare.Win32.CommonName.k skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0025.BIN Infected: not-a-virus:AdWare.Win32.CommonName.k skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0026.BIN Infected: not-a-virus:AdWare.Win32.MyWay.j skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0027.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0027.BIN/cd_htm.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0027.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0028.BIN Infected: not-a-virus:AdWare.Win32.EZula.d skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0030.BIN Infected: not-a-virus:AdWare.Win32.NewDotNet skipped
G:\Data old H disk\download files\iMeshV3.exe/WISE0031.BIN Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
G:\Data old H disk\download files\iMeshV3.exe WiseSFX: infected - 14 skipped
G:\Data old H disk\SOFT\SOFT\irc\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.603 skipped
I:\downloads\BSINSTALL.exe/WISE0024.BIN Infected: not-a-virus:AdWare.Win32.SaveNow.bo skipped
I:\downloads\BSINSTALL.exe WiseSFX: infected - 1 skipped
I:\downloads\BSINSTALL.exe WiseSFX Dropper: infected - 1 skipped
I:\downloads\dgt.exe/data0005 Infected: not-a-virus:AdWare.Win32.SaveNow.bo skipped
I:\downloads\dgt.exe Astrum: infected - 1 skippedScan process completed.
ewido anti-malware - Scan report
+ Created on: 10:16:05, 22/12/2005
+ Report-Checksum: 63869CEE+ Scan result:
:mozilla.6:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.110:C:\Documents and Settings\Derwi\Application Data\Mozilla\Firefox\Profiles\6ogvb6n2.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Derwi\Cookies\derwi@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Derwi\Local Settings\Temp\ASearchAssist.dll -> Adware.Agent : Cleaned with backup
C:\Documents and Settings\Derwi\Local Settings\Temp\res14F.tmp -> Spyware.180Solutions : Cleaned with backup
C:\Program Files\Common Files\Sony Shared\Visualizer\ExlGen.dll -> Dialer.Generic : Cleaned with backup
C:\Program Files\filesubmit\reddragon2.zip\hyperlinker.exe -> Downloader.Small.bke : Cleaned with backup
::Report EndLogfile of HijackThis v1.99.1
Scan saved at 20:09:16, on 12/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dcomcfg.exe
C:\WINDOWS\SOUNDMAN.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\MsnMsgr.exe
F:\soft\Copernic Desktop Search\CopernicDesktopSearch.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\SecuritySuite.exe
C:\Program Files\Internet Explorer\IEXPLORE.exe
C:\WINDOWS\system32\atmclk.exe
I:\downloads\hijackthis\HijackThis.exeR3 - URLSearchHook: (no name) - {83B79436-C1A7-427B-B40D-689E9CC71FAE} - F:\soft\COPERN~1\COPERN~4.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp100.tmp
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Copernic Desktop Search - {C5F7A735-70F1-477F-8C36-6FF3C736017B} - F:\soft\Copernic Desktop Search\CopernicDesktopSearchIntegration977.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SW20] C:\WINDOWS\system32\sw20.exe
O4 - HKLM\..\Run: [SW24] C:\WINDOWS\system32\sw24.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.exe" /background
O4 - HKCU\..\Run: [Copernic Desktop Search] "F:\soft\Copernic Desktop Search\CopernicDesktopSearch.exe" /tray
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [IW_Drop_Icon] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe /DropDisc
O4 - Global Startup: Adobe Reader Snelle start.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Onderzoek - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://kaspersky.com/kos/english/kavwebscan_unicode.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
I hope you can do something with itThomas

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |