ok..lets get rid of this W32/Rbot-ANK first.
Use the following instructions
1.Create a restore point on your pc
2.Download PROCESS EXPLORER freeware to see what processes are running
from
http://www.sysinternals.com/Utilities/ProcessExplorer.html
3. find and kill immediatly process “mswinsck.exe”
4. delete the file “mswinsck.exe” located in C:\Windows\System (seup the computer to show hidden files and system files)
5. Delete the following enteries in the registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Microsoft Winsock
mswinsck.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft Winsock
mswinsck.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Winsock
mswinsck.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft Winsock
mswinsck.exe
HKCU\SYSTEM\CurrentControlSet\Control\Lsa
Microsoft Winsock
mswinsck.exe
HKLM\SYSTEM\CurrentControlSet\Control\Lsa
Microsoft Winsock
mswinsck.exe
HKCU\Software\Microsoft\OLE
Microsoft Winsock
mswinsck.exe
HKLM\SOFTWARE\Microsoft\Ole
Microsoft Winsock
Reboot the computer.
To remove Powerreg scheduler take the following steps
1. Kill these running processes with Task Manager:
%DeskTop%\startup\powerreg scheduler v3.exe
%Profile%\start menu\programs\startup\powerreg scheduler.exe
%Profile%\start menu\programs\startup\powerreg schedulerv2.exe
%Startup%\powerreg scheduler v3.exe
%Startup%\powerreg scheduler.exe
%SystemRoot%\desktop\startup\powerreg scheduler.exe
%SystemRoot%\start menu\programs\startup\powerreg scheduler v3.exe
%SystemRoot%\start menu\programs\startup\powerreg scheduler.exe
2. Remove these files (if present) with Windows Explorer:
%DeskTop%\startup\powerreg scheduler v3.exe
%DeskTop%\startup\webshots.lnk
%Profile%\start menu\programs\startup\powerreg scheduler.exe
%Profile%\start menu\programs\startup\powerreg schedulerv2.exe
%ProgramFiles%\powerreg
%Startup%\powerreg scheduler v3.exe
%Startup%\powerreg scheduler.exe
%SystemRoot%\desktop\startup\powerreg scheduler.exe
%SystemRoot%\start menu\programs\startup\image.lnk
%SystemRoot%\start menu\programs\startup\norton disk doctor.lnk
%SystemRoot%\start menu\programs\startup\powerreg scheduler v3.exe
%SystemRoot%\start menu\programs\startup\powerreg scheduler.exe
3. Remove these directories (if present) with Windows Explorer:
%DeskTop%\startup
update your spysweeper programme and ewido security suite.
Now download smitrem from
http://noahdfear.geekstogo.com/click counter/click.php?id=1
and save to desktop.
Double click on the file to extract it to c:\smitrem.
Now reboot to safemode and Open the c:\smitrem folder and double click the RunThis.bat file to start the tool.
Follow the prompts on screen and wait for the tool to complete and disk cleanup to finish.
When the tool is finished, it will will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or the partition where your operating system is installed. Examining that log should show that the infection was cleaned.
And now run a full scan of both ewido and Spysweeper, and they should remove the remaining malware in the computer.
run a fresh MWAV scan and post the log.