Home › Forums › Archives › Computer Support › Computer Support Discussion › PSW.Bispy.B
- This topic has 6 replies, 5 voices, and was last updated 21 years, 8 months ago by
kron_19792000.
-
AuthorPosts
-
December 21, 2004 at 1:57 am #15469
Sh8keS 32
MemberDoes anyone know how to remove the PSW.Bispy.B trojan horse? Is there a program on how to remove it. I have also contracted a virus called “bobby” and I do not know how to remove it as well, and cannot find a program that can do the task either. So if anyone knows how to remove them Please post, it will muchly be appreciated.
December 21, 2004 at 2:01 am #109451kyuubi
Memberuse a AV or use this
December 21, 2004 at 2:15 am #109449Sh8keS 32
MemberI just used that program and it says I have no trojans on my computer, while AVG insists otherwise.. It says I have PSW.Bispy.B , but cannot remove it. It successfull removed the “bobby” virus.
December 21, 2004 at 2:17 am #109448MartinBradley
MemberOdd that – I did a search on Symantec for the trojan you specify and it came up with absolutely nothing.
December 21, 2004 at 2:31 am #109447detn8r
ParticipantHow do you get rid of trojan horse PSW Bispy B? c/o Google.com.
December 22, 2004 at 11:41 pm #109450Sh8keS 32
MemberHere is my Hijack this Logfile:
Logfile of HijackThis v1.99.0
Scan saved at 10:29:29 PM, on 12/21/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSExplorer.EXE
C:PROGRA~1GrisoftAVGFRE~1avgamsvr.exe
C:PROGRA~1GrisoftAVGFRE~1avgupsvc.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32yqrkkw.exe
C:PROGRA~1GrisoftAVGFRE~1avgcc.exe
C:PROGRA~1GrisoftAVGFRE~1avgemc.exe
C:Program FilesHewlett-PackardDigital Imagingbinhpotdd01.exe
C:Program FilesInternet Exploreriexplore.exe
C:unzippedhijackthisHijackThis.exeR0 – HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com/
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoo.com
R0 – HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 – HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = 127.0.0.1
O1 – Hosts: 69.20.16.183 ieautosearch
O1 – Hosts: 69.20.16.183 auto.search.msn.com
O1 – Hosts: 69.20.16.183 search.netscape.com
O1 – Hosts: 69.20.16.183 ieautosearch
O1 – Hosts: 69.20.16.183 ieautosearch
O1 – Hosts: 69.20.16.183 ieautosearch
O2 – BHO: Google Toolbar Helper – {AA58ED58-01DD-4d91-8333-CF10577473F7} – c:program filesgooglegoogletoolbar1.dll
O3 – Toolbar: &Google – {2318C2B1-4965-11d4-9B18-009027A5CD4F} – c:program filesgooglegoogletoolbar1.dll
O4 – HKLM..Run: [DeadAIM] rundll32.exe “C:PROGRA~1AIM\DeadAIM.ocm”,ExportedCheckODLs
O4 – HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 – HKLM..Run: [QuickTime Task] “C:Program FilesQuickTimeqttask.exe” -atboottime
O4 – HKLM..Run: [kalvsys] C:windowssystem32kalvgsg32.exe
O4 – HKLM..Run: [AVG7_CC] C:PROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP
O4 – HKLM..Run: [AVG7_EMC] C:PROGRA~1GrisoftAVGFRE~1avgemc.exe
O4 – HKCU..Run: [Yahoo! Pager] C:Program FilesYahoo!Messengerypager.exe -quiet
O4 – HKCU..Run: [Washee] C:Program FilesWasheeWashee.exe FirstTime
O4 – Global Startup: hp psc 2000 Series.lnk = C:Program FilesHewlett-PackardDigital Imagingbinhpobnz08.exe
O4 – Global Startup: hpoddt01.exe.lnk = ?
O4 – Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 – Extra context menu item: &AOL Toolbar search – res://C:Program FilesAOL Toolbartoolbar.dll/SEARCH.HTML
O8 – Extra context menu item: &Google Search – res://C:Program FilesGoogleGoogleToolbar1.dll/cmsearch.html
O8 – Extra context menu item: Backward Links – res://C:Program FilesGoogleGoogleToolbar1.dll/cmbacklinks.html
O8 – Extra context menu item: Cached Snapshot of Page – res://C:Program FilesGoogleGoogleToolbar1.dll/cmcache.html
O8 – Extra context menu item: Similar Pages – res://C:Program FilesGoogleGoogleToolbar1.dll/cmsimilar.html
O8 – Extra context menu item: Translate into English – res://C:Program FilesGoogleGoogleToolbar1.dll/cmtrans.html
O9 – Extra button: AIM – {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} – C:Program FilesAIMaim.exe
O9 – Extra button: (no name) – {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} – (no file)
O9 – Extra button: Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:Program FilesMessengermsmsgs.exe
O9 – Extra ‘Tools’ menuitem: Windows Messenger – {FB5F1910-F110-11d2-BB9E-00C04F795683} – C:Program FilesMessengermsmsgs.exe
O16 – DPF: Arcsoft Web Uploader – http://www.hpphoto.com/downloads/ReadFileApplet.cab
O16 – DPF: {1DF36010-E276-11D4-A7C0-00C04F0453DD} (Stamps.com Secure Postal Account Registration) – https://secure.stamps.com/download/us/registration/3_0_0_804/sdcregie.cab
O16 – DPF: {3CF32649-D1C0-4F42-AB44-ED284748920B} – http://www.merriam-webster.com/toolbar/webinstall.cab
O16 – DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) – http://207.188.7.150/17563ce7ec14ff5d8200/netzip/RdxIE601.cab
O16 – DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} – http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey/us/win/QuickTimeInstaller.exe
O16 – DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) – http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 – DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) – http://www.napster.com/client/isetup.cab
O16 – DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) – http://oldglory.ninesystems.com/AxisCamControl.ocx
O16 – DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} – http://install.wildtangent.com/bgn/partners/shockwave/slyder/install.cab
O23 – Service: AVG7 Alert Manager Server – GRISOFT, s.r.o. – C:PROGRA~1GrisoftAVGFRE~1avgamsvr.exe
O23 – Service: AVG7 Update Service – GRISOFT, s.r.o. – C:PROGRA~1GrisoftAVGFRE~1avgupsvc.exe
O23 – Service: ISEXEng – Unknown – C:WINDOWSSystem32angelex.exe (file missing)
O23 – Service: Pml Driver HPZ12 – HP – C:WINDOWSSystem32HPZipm12.exe
O23 – Service: Symantec Network Drivers Service – Symantec Corporation – C:Program FilesCommon FilesSymantec SharedSNDSrvc.exeWhat seems hazardous or needs to be deleted?
December 23, 2004 at 2:53 am #109452kron_19792000
Memberhttp://forums.techguy.org/f54-s.html
Go there and post u’r hijack log you will get a better answer. I just had a glance at the log I do not think there is anything seriously wrong, I just saw that you have your hosts redirecting you to some site called ieautosearch. You seem to have a few minor problems post your log we will try to help you there. -
AuthorPosts
- You must be logged in to reply to this topic.