Anti-spyware identifies but cannot eliminate the following threats:

J

JJS

Up until a few days ago MSASPW was doing a terrific job
identifying and eliminating any spyware threats.

But recently I picked up the following bugs, ASPW
identifies and says it has eliminated them but they
immediately reappear:

Transponder.ABetterInternet.Aurora
Infected files detected
C:\WINDOWS\svcproc.exe

Transponder.ABetterInternet.DrPMon
Trojan.Startup.0e3df3
Infected files detected
C:\WINDOWS\system32\DrPMon.dll

Infected files detected
c:\windows\system32\dcaokw.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run oaepyh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run oaepyh

Any suggestions as to how to eliminate these pests? When
I search the file locations they are no where to be found.

Thanks in advance for any help.
 
M

Mikolaj

Up until a few days ago MSASPW was doing a terrific job
identifying and eliminating any spyware threats.

But recently I picked up the following bugs, ASPW
identifies and says it has eliminated them but they
immediately reappear:

Transponder.ABetterInternet.Aurora
Infected files detected
C:\WINDOWS\svcproc.exe

Transponder.ABetterInternet.DrPMon
Trojan.Startup.0e3df3
Infected files detected
C:\WINDOWS\system32\DrPMon.dll

Infected files detected
c:\windows\system32\dcaokw.exe

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run oaepyh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi
on\Run oaepyh

Any suggestions as to how to eliminate these pests? When
I search the file locations they are no where to be found.

Thanks in advance for any help.

You can try this way:

Start the computer in the Safe mode (F8 during boot-up), run Windows
Explorer, go to your profile temporary folders (usually C:\Documents and
Settings\username\local settings\temp and c:\Documents and
Settings\username\local settings\Temporary Internet Files\Content.IE5) and
delete all the files in those directories and subdirectories.
Then do a full system scan with MS AntiSpyware (check the proper option
under Scan settings). Also using some other "cleaning" software such as:

Spybot Search&Destroy http://www.majorgeeks.com/download2471.html
HijackThis http://www.majorgeeks.com/download3155.html
CWShredder http://www.majorgeeks.com/download3019.html
Ad-Aware SE Personal http://www.lavasoft.com/software/adaware/
McAfee Stinger http://vil.nai.com/vil/stinger/

If you run HijackThis you can check the log it prepares - just copy and
paste it to the http://www.hijackthis.de web page and click analyze button.
 
L

Le Roy

i have the exact same problem. My Norton Anti-Virus also
detects it, but cannot delete it, the same with Ad-Aware!

I can manually find the files, but cant delete it. I have
also notices the program creates folders in the "temp"
folder and tries to access the internet from there. Each
time you delete it, it just comes back again.

I have also noticed some strange files in my
windows/system32 folder: "wspvgci" is identified as
spyware by Norton Anti-Virus. I found that file thanks to
Registry Clearer. The file is in the Startup list of
Windows, so it starts each time windows is launched.

That is all the info i have on the programs so far.
Please help!
 
J

JohnF.

I just did battle with Aurora this week and ABIRemover did nothing to help.
It may be evolving.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top