Unsolved

This post is more than 5 years old

543

June 1st, 2006 00:00

My HJT Logfile

Hey, for the past few days my computer's internet has been running very slowly.  Games have been very laggy, and sites like google video, youtube, gamespot have very slow videos now.  I want to know what is causing this problem, if its even a virus. 
 
Anyways I ran Ad Aware and these are some of the thingsthat were on if it might help: (THESE ARE JUST A FEW OF THE THINGS, PLEASE TELL ME IF I SHOULD GET RID OF THEM ALONG WITH THE OTHERS OR NOT)

References detected during the scan:

»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Adware.P2PNetworking(TAC index:3):10 total references

AlfaCleaner(TAC index:10):3 total references

Malware.SpywareStrike(TAC index:5):17 total references

Tracking Cookie(TAC index:3):95 total references

 

There are 125 new ciritcal objects, and I dont noe if I get rid of some of them or what.  Here are some examples:

Name- AdwareP..      Type- Regkey        Category- Adware             Object- HKEY_CLASS_ROOT:cls.....

Alfa Cleaner                  Type- Regvalue       Category- Misc                  HKEY_CLASS_ROOT....

Malware....                   Type- Regkey                      Category- Malware          HKEY_CLASS_ROOT

 

Tracking....                     IECahche                      Dataminer                           Cookie: kaka@valueclick.com/...

 

 

As for the HJT LogFile, this is it:
Logfile of HijackThis v1.99.1
Scan saved at 9:40:08 PM, on 5/31/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb12.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\Documents and Settings\KAKA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO:   - {98d50a88-5056-4ca7-a3b1-c16e00ecdd77} - C:\WINDOWS\System32\nmd.dll
O2 - BHO:   - {9bdc2c3a-5375-4248-b130-2c1bd44aebb5} - C:\WINDOWS\System32\ij.dll
O2 - BHO:   - {a8e6f8de-f964-44a8-a5dd-a8fe622f2b4f} - C:\WINDOWS\System32\jnn.dll
O2 - BHO:   - {bd80b88d-0b8d-4474-a399-0262d6ea2acc} - C:\WINDOWS\System32\nf.dll
O2 - BHO:   - {dc1e3c5e-12ca-47ad-bdc8-a19be0e62b2d} - C:\WINDOWS\System32\we.dll
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/haphazard/raptisoftgameloader.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kavwebscan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136849239576
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138402583077
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\WCAVUSD.DLL (file missing)
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)

Thanks for all of the help, my computer isnt running slow, its only the internet.

Message Edited by Undertaker_282 on 05-31-200608:49 PM

220 Posts

June 1st, 2006 09:00

Hello there .

Your computer is in need a little TLC but it is nothing that we can not sort for you. Please make sure that each step is complete before moving on to the next one. May I suggest that you either print out these instructions or save them as a text file with Notepad or your default text editor to your desktop as we will be restarting into Safe Mode later on in the fix. If you are having any difficulty understanding or following any part of the instructions then please feel free to enquire so that we can clarify things in more detail. Make sure you take your time with this fix and make sure you set enough time to complete it in one task. I would suggest reading through it all before proceeding.

I notice that you use P2P type programs (file sharing) While this seems a good idea for free stuff it usually come with a price. Around 50% of the programs that are used for file sharing come with some sort of malware payload. Then there is the problem of viruses/trojans which some files carry amongst the file sharing community, then on top of that there is of course the legal status of it all. The safest way is to play it clean, if you like a program then respect the authors wishes and buy the original product !!

Lets download an additional program for scanning your computer
Please download Ewido Security Suite it is a free version of the program.

Install ewido security suite
When installing, under "Additional Options" uncheck..
Install background guard
Install scan via context menu

Launch ewido, there should be an icon on your desktop, double-click it.
The program will now open to the main screen.
When you run ewido for the first time, you will get a warning " Database could not be found!". Click OK. We will fix this in a moment.
You will need to update ewido to the latest definition files.

On the left hand side of the main screen click Update.
Then click on Start Update.

The update will start and a progress bar will show the updates being installed. The status bar at the bottom will display "Update successful"
Now Close Ewido for the time being, do not scan just yet

Next Lets ensure that all hidden files are set to show
Open the Windows Explorer - Tools - Folder Options - and select the View tab:
Scroll down to where it says " Hidden Files and Folders" section.
Now select the option to " Show hidden files and folders"
Take the tick out of " Hide file extensions for known file types"
Take the tick out of " Hide protected operating system files" Click on OK and Apply
Next Click the " Apply to all Folders" button. Close Windows Explorer.

Next I want to double check a file does not contain anything malicious
Navigate to virus total --> http://www.virustotal.com/en/indexf.html

Click on the choose button and navigate to the file below, once you have located this file press the send button and wait for the file to be scanned for any viruses. Let me know the results in the next post.

File to submit --> C:\Program Files\MSN\MSNCoreFiles\ msn.exe

Open HJT by double clicking on the icon and select the second button entitled "do a system scan only".
Make sure you close any windows that are open or minumised

Now select the followng entries by placing a tick in the left hand check box

O2 - BHO: - {98d50a88-5056-4ca7-a3b1-c16e00ecdd77} - C:\WINDOWS\System32\nmd.dll
O2 - BHO: - {9bdc2c3a-5375-4248-b130-2c1bd44aebb5} - C:\WINDOWS\System32\ij.dll
O2 - BHO: - {a8e6f8de-f964-44a8-a5dd-a8fe622f2b4f} - C:\WINDOWS\System32\jnn.dll
O2 - BHO: - {bd80b88d-0b8d-4474-a399-0262d6ea2acc} - C:\WINDOWS\System32\nf.dll
O2 - BHO: - {dc1e3c5e-12ca-47ad-bdc8-a19be0e62b2d} - C:\WINDOWS\System32\we.dll
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\WCAVUSD.DLL (file missing)


Once you have selected all entries then click once on the " fix checked" button to clear the entries from your log

Please re-start your computer in safe mode - You may want to print the rest of these instructions from here onwards
To do so, reboot your computer and repeatedly tap the F8 whilst your computer is booting up (just before the MS Windows flag screen appears) until a menu appears. Once you see the menu select the option to start the computer in safe mode. (It might take more than go to access the menu if you have not done this before, just simply reboot the machine again and repeat the steps)

Now click on the ewido icon on your desktop to start it (or locate the program from your start menu)

Click on Scanner
Click on Complete System Scan and the scan will begin.
You will be prompted to clean the first infection.
Select " Perform action on all infections", then proceed.
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
Click Save report.
Save the report .txt file to your desktop or a location where you can find it easily.

Next we need to locate the following Files
Once you find them (if they exist), click on the file to highlight it first, then press and hold down the shift key then press delete at the same time to bypass your recycle bin. If any do not exist just move on to the next file in line and note down the filename/s

--> C:\WINDOWS\System32\nmd.dll
--> C:\WINDOWS\System32\ij.dll
--> C:\WINDOWS\System32\jnn.dll
--> C:\WINDOWS\System32\nf.dll
--> C:\WINDOWS\System32\we.dll
--> C:\WINDOWS\system32\WCAVUSD.DLL (file missing)

Now reboot your computer and allow it to start normally again
Once your computer has reboot generate a fresh HJT log and send it to me along with your ewido results and not forgetting the virus total result too- Thanks

June 1st, 2006 20:00

Hey it Worked!  Thanks a lot now I can post it. 

HJT LogFile: Logfile of HijackThis v1.99.1
Scan saved at 2:33:52 PM, on 6/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb12.exe
C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\AIM95\aim.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\System32\ctfmon.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\KAKA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*http://www.yahoo.com
F2 - REG:system.ini: UserInit=userinit.exe
O3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\PROGRA~1\COMMON~1\VERIZO~1\SFP\vzbb.dll (file missing)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb12.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: RaptisoftGameLoader - http://www.miniclip.com/haphazard/raptisoftgameloader.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWeb.Scan Object) - http://www.kaspersky.com/downloads/kws/kavweb.scan_unicode.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136849239576
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1138402583077
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: STOPzilla Local Service - Unknown owner - C:\Program Files\STOPzilla!\szntsvc.exe (file missing)

Message Edited by Undertaker_282 on 06-01-200604:23 PM

June 1st, 2006 20:00

Virus Total

STATUS: FINISHEDComplete scanning result of "msn.exe", received in VirusTotal at 06.01.2006, 18:57:55 (CET).

Antivirus Version Update Result
AntiVir 6.34.1.37 06.01.2006  no virus found
Authentium 4.93.8 05.31.2006  no virus found
Avast 4.7.844.0 06.01.2006  no virus found
AVG 386 06.01.2006  no virus found
BitDefender 7.2 06.01.2006  no virus found
CAT-QuickHeal 8.00 06.01.2006  no virus found
ClamAV devel-20060426 05.31.2006  no virus found
DrWeb 4.33 06.01.2006  no virus found
eTrust-InoculateIT 23.72.23 06.01.2006  no virus found
eTrust-Vet 12.6.2237 06.01.2006  no virus found
Ewido 3.5 06.01.2006  no virus found
Fortinet 2.77.0.0 05.31.2006  no virus found
F-Prot 3.16f 05.31.2006  no virus found
Ikarus 0.2.65.0 06.01.2006  no virus found
Kaspersky 4.0.2.24 06.01.2006  no virus found
McAfee 4775 06.01.2006  no virus found
Microsoft 1.1441 06.01.2006  no virus found
NOD32v2 1.1573 06.01.2006  no virus found
Norman 5.90.17 06.01.2006  no virus found
Panda 9.0.0.4 05.31.2006  no virus found
Sophos 4.05.0 06.01.2006  no virus found
Symantec 8.0 06.01.2006  no virus found
TheHacker 5.9.8.152 06.01.2006  no virus found
UNA 1.83 05.30.2006  no virus found
VBA32 3.11.0 05.31.2006 no virus found


Aditional Information
File size: 93696 bytes
MD5: 7d24308ea278202b1fb92541dbf3ec84
SHA1: 98a7a0c781698dfc941d8f0e691573b457b2488f

Ewido: ---------------------------------------------------------
 ewido anti-malware - Scan report
---------------------------------------------------------

 + Created on:   2:20:07 PM, 6/1/2006
 + Report-Checksum:  A1224FE9

 + Scan result: -------I HAD TO POST A DOT AFTER ALL OF THE B's BECAUSE IT SAID I CANT POST THE WORDS B       S.  SO IF YOU GET CONFUSED PLEASE WRITE IT

 C:\Documents and Settings\KAKA\Cookies\kaka@122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ad.doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@adbrite.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ads.realcastmedia[1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ads43.bpath[1].txt -> TrackingCookie.Bpath : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@anat.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@as-eu.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@as1.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@b.s.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@cb.s.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@com[2].txt -> TrackingCookie.Com : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@cs.sexcounter[2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@data3.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@data4.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@e-2dj6wflowhcpcko.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@e-2dj6wjlyggcjckq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@e-2dj6wjnychdzieq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@e-2dj6wjnyuncpogq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-accuweather.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-ati.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-bcstore.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-campmor.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-c.b.s.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup ---- I had to put a dot after c because i cant post the words b   s, so its really only 1 dot at the end of s, same with all of the others
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-clearchannel.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-console.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-dig.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-friendster.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-geardirect.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-hollywoodmedia.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-ignitemedia.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-inforspaceinc.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-nvidia.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-penguingroupusa.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-sonycomputer.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-speakeasy.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-tienda.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg-zoomerang.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@ehg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@fhm.valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@focusin.ads.targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@h.starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@install.bestoffersnetworks[2].txt -> TrackingCookie.Bestoffersnetworks : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@npr.valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@pmads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@powellsbooks.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@sales.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@sel.as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@sel.as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@sonycorporate.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@sonymediasoftware.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@spylog[2].txt -> TrackingCookie.Spylog : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@stats.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@torstardigital.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@trafficcenter[1].txt -> TrackingCookie.Trafficcenter : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@valueclick[3].txt -> TrackingCookie.Valueclick : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@vdn.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@w123.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@weborama[2].txt -> TrackingCookie.Weborama : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@www.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@www.starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
 C:\Documents and Settings\KAKA\Cookies\kaka@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
 C:\Documents and Settings\KAKA\Desktop\backups\backup-20060601-130332-390.dll -> Logger.Small.ee : Cleaned with backup
 C:\Documents and Settings\KAKA\Desktop\backups\backup-20060601-130332-838.dll -> Logger.Small.ee : Cleaned with backup
 C:\Documents and Settings\KAKA\Desktop\backups\backup-20060601-130332-861.dll -> Logger.Small.ee : Cleaned with backup
 C:\Documents and Settings\KAKA\Desktop\backups\backup-20060601-130333-389.dll -> Logger.Small.ee : Cleaned with backup
 C:\Documents and Settings\KAKA\Desktop\backups\backup-20060601-130333-781.dll -> Logger.Small.ee : Cleaned with backup
 C:\Documents and Settings\KAKA\Local Settings\Temp\win.exe -> Logger.Small.ee : Cleaned with backup
 C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup
 C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1154\A0391932.dll -> Logger.Small.ee : Cleaned with backup
 C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1154\A0391933.dll -> Logger.Small.ee : Cleaned with backup
 C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1154\A0391934.dll -> Logger.Small.ee : Cleaned with backup
 C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1154\A0391935.dll -> Logger.Small.ee : Cleaned with backup
 C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1154\A0391936.dll -> Logger.Small.ee : Cleaned with backup
 C:\WINDOWS\SYSTEM32\oleext.dll -> Trojan.Small.ev : Cleaned with backup


::Report End

The HJT LogFile I posted before this post was from a few hours ago, tell me if I should post one from right now

220 Posts

June 1st, 2006 20:00

Hi there Undertaker_282 , glad you got the posting problem sorted, nice one :)

Good news all round... Your log is looking malware free. Just a little updating to do to keep things in touch...

Update your Java.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components.

Close any programmes you may have running, ESPECIALLY your web browser
Click Start > Control Panel.
Click Add/Remove Programs.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove or Change/Remove button.
Repeat as many times as necessary to remove all versions of Java.
Reboot your computer once all Java components are removed.

Then download the latest version of and install it to your computer.

I would strongly advise that you update your windows operating system and install service pack 2. This is a free download and can be found at microsofts website This is fairly lenthy download. If you cannot download SP2 via Microsoft Update, you can order it on CD from the download page. This is a big update for your system and may take some time to install

Now you are free from any signs of malware I am posting my all clear speech,
Please take time and read though it and feel free to ask any further questions, or leave any comments that you wish :)

Please advise on any problems that you may still be experiencing.

First lets rehide your System Files
  • ClickStart.
  • Open My Computer.
  • SelectTools menu
  • Click Folder Options.
  • Select the View Tab.
  • Uncheck Show hidden files and folders in the Hidden files and folders section.
  • Select Hide protected operating system files (recommended) option.
  • Check the Hide file extensions for known file types option.
  • ClickYes.
  • Click OK
Next lets reset your system restore points please follow these simple steps in order:

  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Clickthe System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.


  • Restart your computer


  • Turn ON System Restore.
  • On the Desktop, right-clickMy Computer.
  • Click Properties.
  • Click theSystem Restore tab.
  • Un-Check Turn off System Restore.
  • Click Apply, and then clickOK.
Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialise and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

Make sure you are protected with a known anti-virus checker and a firewall
Windows XP will supply its own firewall but it will only monitor traffic in one direction

Recommended Anti-Virus Programs

There are many antivirus products out there, and at first, with there being so many different products it may look confusuing to you, some are free products and others are fully licienced products. It is up to you which you go for. For free antivirus product I would be looking at either Avast Home edition or AVG Free edition. If you are going to be looking at fully licienced software then I would seriously consider either Nod32 or kaspersky Antivirus products, both are excellent in their job of keeping viruses at bay.

Recommended Firewalls

Firewalls.... A firewall serves as a program that monitors ports, connections and programs, both incomming and outgoing from your computer. Windows does come with its own firewall but unfortunatly it only monitors traffic in one direction. As a result we advise that you install your own independant firewall. Two good firewalls you can choose from (both are free) are Sunbelt Kerio Firewall and also Zonealarm As with the above anti virus packages, both are excellent in their job.

Please note.... only ever install one anti virus product and one firewall, if you try running more than one antivirus on your computer they will conflct and cause problems with each other. Once you have these products installed and on board your computer the next thing is to update your anti virus, this will check for the latest virus definitions so that your anti virus can detect the latest viruses. One you have updated then you should run a full complete scan on your computer, this may take some time but it is highly advisable that you let this finish on its own accord.

Next, if they're not already present, I would reccomend the download and installation of some or all of the following programs (Unlike firewalls and virus checkers you can run more than one application at once, feel free to download ALL of the below if you wish)
  • Ad-Aware SE - This is a program that scans for and removes known spyware from your machine.
  • Spybot Search & Destroy - Spybot is a tool like Ad-Aware SE whereas it seeks out and removes known spyware from your machine. These two tools (Ad-Aware & spybot) are perfect complements to each other as one will most always find something the other missed.
  • Spyware Blaster - By altering your registry, this program stops harmful sites from installing things like ActiveX Controls on your machines.
  • IE_Spyad - Works by placing known "bad" sites into your Internet Explorer "Restricted Zones" prohibiting them from doing potentially problematic things to your computer.
For added protection you may also like to add a host file, for more information regarding host files read here

Once you have installed and updated any malware solution tools you must remember to update regularly, I would advise at least a manual check of once a week as well as any auto scheduled checks.

Take care and happy surfin......

Dorian - aKa Steve

June 1st, 2006 21:00

Thanks a lot Dorian, this wasnt so hard and you replied and posted fast.  Thanks

Message Edited by Undertaker_282 on 06-01-200605:07 PM

No Events found!

Top