1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Ncase, Com.Com, & EVID Hacktool

Discussion in 'Malware and Virus Removal Archive' started by timeoutgang, 2006/12/31.

  1. 2006/12/31
    timeoutgang

    timeoutgang Inactive Thread Starter

    Joined:
    2006/05/09
    Messages:
    148
    Likes Received:
    0
    Hi guys, hope you are all well.
    No major problems with my PC or my sons laptop, thanks to you.
    Just ran a panda scan online & the following were found. Adaware, spybot & AVG all missed these. Firstly, how do I get rid of them, and more importantly, why didn't my security programs pick them up?

    Adware/ncase, found in, C:\Windows\didduid.ini

    Adware/sidesearch, found in, C:\Program Files\Lycos

    Spyware/cookie/cqu-bin, found in C:\Documents & Settings\daf\cookies\daf@cqi-bin[1].txt

    Spyware/cookie/com.com, found in C:\Documents & Settings\daf\cookies\daf@com[1].txt

    Spyware/cookie/go, found in C:\Documents & Settings\daf\cookies\daf@go[1].txt

    Spyware/cookie/com.com, found in C:\Documents & Settings\owner\cookies\owner@com[1].txt

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix\process.exe

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix.zip[smitfraud\process.exe]

    Hacktool/evid, found in, C:\Program Files\pplice tv\synalivesetup.exe[evid4226patch.exe]

    Thanks, in advance & a Very Happy & Prosperous New Year!
     
  2. 2006/12/31
    Bill Castner

    Bill Castner Inactive

    Joined:
    2006/08/30
    Messages:
    1,980
    Likes Received:
    0
    Open IE and empty your Temporary Internet Files, and your cookies.

    Then for the rest, just delete them:

    Adware/ncase, found in, C:\Windows\didduid.ini

    Adware/sidesearch, found in, C:\Program Files\Lycos

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix\process.exe

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix.zip[smitfraud\process.exe]

    Hacktool/evid, found in, C:\Program Files\pplice tv\synalivesetup.exe[evid4226patch.exe]


    Consider too that some of these entries are false positives. For example, these two are false positives:

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix\process.exe

    Potentially unwanted tool:Application/processor, found in, C:\Documents & Settings\owner\desktop\smitfraudfix.zip[smitfraud\process.exe]

    Finally, a lot of programs do not care about Cookies. Cookies can show signs of infection, but are not themselves infectors.
     

  3. to hide this advert.

  4. 2006/12/31
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    H TOG

    The below references evid4226patch.exe is also a false positive.

    It is a utility to set the number of half open connections. Usually used to increase the speed P2P programs like Emule Limewire etc.

    Dosen't come with them, but someome there may have downloaded it.

    Probably installed by the C:\Program Files\pplice tv\synalivesetup.exe for a speedup.

    See
    http://www.lvllord.de/

    Spybot and Adaware know about these and correctly did not report them as malware.

    Keep your Spy/Adware scanners up to date. And run them ocassionally in Safe mode.

    Here is an additional Spy/Adware cleaner
    http://www.xblock.com/download/xclean_micro.exe

    Below are some Disk Temp and Registry cleanup utilities you might consider
    DCleaner http://www.majorgeeks.com/DCleaner_d4790.html

    ATF-Cleaner http://www.atribune.org/content/view/25/2/

    CCleaner get the slim version http://www.ccleaner.com/download/builds.aspx


    Mike
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.