This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My PC is infected...

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi ya guys….i'm pretty new to the PC and recently PC is infected.It started with my PC rebooting itself everytime after McAfee updates itself and yesterday it got worse :( .
Starnge pop-ups which never happened before pop-ups everytime a new window opens,strange .exe programs is generated everytime the IE is open and (Malware i think)is detected by McAfee VirusScan, my Firewall is disable automatically during each start up,there's a i dont know what program i think "intell32" which i think i have manage to remove,my wallpaper for the desktop is replaced by a strange add with a "warning" on it and the PC runs slow than it normally does :wacko: …..

I have read a few threads here and i understand that i have to post a log file from Hijack This, so here it is:
Logfile of HijackThis v1.99.1
Scan saved at 5:37:56 PM, on 8/27/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\MY DOCUMENTS\DOWNLOADED FILES\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
O2 - BHO: Class - {0EE2CAAC-3DCF-1013-715F-E515DBC8675D} - C:\WINDOWS\SYSTEM\NETVX.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab

I really hope someone can help me to look thru with this problem i'm having :oops: …..
*Bump :(

Ok here's an update of whats still going on in my PC :confused: …
-Everytime a new IE window opens a new .exe (Malware i believe)seems to generate and is detected by McAfee VirusScan plus there's this "jcekl.dll" which is also remove by VirusScan saying that its infected by the StartPage-DU.dll virus and plus the pop ups too.
-My Firewall is disabled automatically at each startup and i have to enable it manually :wacko: …
-What used to be a green background behind the wallpaper is now a black screen, which i think used to be the background of the warning page which i described above.
-And the PC seems to be very slow after startup before it can resume as normal.

Well and here's an update of the Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 9:45:50 AM, on 8/28/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\MY DOCUMENTS\DOWNLOADED FILES\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.kerrazy-torrrents.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
O2 - BHO: Class - {0EE2CAAC-3DCF-1013-715F-E515DBC8675D} - C:\WINDOWS\SYSTEM\NETVX.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab
Download cwshreadder http://cwshredder.net/bin/CWShredder.exe

Reboot in safemode.
Close all programs leaving only HijackThis running. Place a check against each of the following, Click on Fix Checked when finished and exit HijackThis.
O2 - BHO: Class - {0EE2CAAC-3DCF-1013-715F-E515DBC8675D} - C:\WINDOWS\SYSTEM\NETVX.DLL


Then run CWShreadder.


Reboot post another hijackthis log.
Hiya little eagle :) …first off thanks for helping me out with the PC issues i'm having.
Ok here it goes…before i read your reply i did a PandaActive Scan for the Local HDD and here is the report i saved:

Incident                                    Status                        Location

Spyware:spyware/betterinet    No disinfected  C:\WINDOWS\SYSTEM\in10b6s.dll
Adware:Adware/nCase            No disinfected  C:\WINDOWS\SYSTEM\SplWbr.dll
Adware:Adware/SearchAid      No disinfected  C:\WINDOWS\SYSTEM\hiaa.dll
Adware:Adware/nCase            No disinfected  C:\WINDOWS\SYSTEM\msbb321.dll
Adware:adware/navipromo      No disinfected  C:\WINDOWS\SYSTEM\sdkid32.exe
Spyware:spyware/smitfraud    No disinfected  C:\WINDOWS\SYSTEM\oleext.dll
Adware:Adware/NetPals          No disinfected  C:\WINDOWS\Downloaded Program Files\ATPartners.inf
Adware:Adware/SearchAid      No disinfected                C:\ms32.tmp


So i did as you instructed and ran Hijack This in "Safe Mode" checked and fix.After that i ran CWShredder and the report came as no CoolWebSearch is found.

After i reboot the PC the first thing noticed is that the McAfee firewall is still disabled automatically, my homepage is now "about:blank"…but no .exe is generated once a new IE window is opened.So thats an improvement… :D

So here is the new Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 5:55:25 PM, on 8/28/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\MY DOCUMENTS\DOWNLOADED FILES\HIJACKTHIS.EXE

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\jcekl.dll/sp.html#21044
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system\jcekl.dll/sp.html#21044
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
R3 - Default URLSearchHook is missing
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\McUpdate.exe
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200404…meInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/…trolLite_EN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab

:) Hope to hear from ya soon..
Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe


Download http://www.derbilk.de/SpSeHjfix109.zip into a folder.
Unzip SpSeHjfix109.zip. (don't run it yet)


1. Open My Computer
2. Right click on your hard drive that you wish to clean (C drive, for example)
3. In the context menu that opens, select properties
4. Under the general tab you should select Disk Cleanup
5. Windows will scan your drive which will take a few seconds/minutes
6. A box will display the various files you can remove.
Check all boxes except compress old files (If listed)
7. Click OK and windows will comply.



Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'.




run it in safe mode and run it twice
I downloaded the CWShredder and the SpSeHjfix109 as you directed.I did a disk cleanup twice before rebooting the PC to Safe Mode and running the SpSeHjfix109.But the PC did not reboot by itself…..kinda odd as i was waiting for my PC to restart but it never did.
I didnt know exactly to run the CWShredder in Safe Mode or in Normal mode so i did the process twice for each :oops: ….and same results after running SpSeHjfix109 the PC did not restart.
So here's the log for the SpSeHjfix109 in Safe Mode as you instructed and the Hijack This log in Normal mode:
 **** Run Keys ****

RUN: [SystemTray] SysTray.Exe 
RUN: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme 
RUN: [EnsoniqMixer] starter.exe 
RUN: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe 
RUN: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe 
RUN: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook 
RUN: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask 
RUN: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe" 
RUN: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe 
RUN: [LoadQM] loadqm.exe 
RUN: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE 


 **** Browser Helper Objects ****



 **** IE Toolbars ****

TOOLBAR: [McAfee VirusScan] C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL 
TOOLBAR: [&Radio] C:\WINDOWS\SYSTEM\MSDXM.OCX 


 **** IE Extensions ****

IEExt: [Web Browser Applet Control] C:\WINDOWS\SYSTEM\MSJAVA.DLL 


 **** Hosts File Entries ****



 **** IE Settings ****

IEBypass:   
Local Page: C:\WINDOWS\SYSTEM\blank.htm 


 **** IE Context Menu (Right click) ****



 **** Layered Service Providers ****

LSP: MS.w95.spi.tcp 
LSP: MS.w95.spi.udp 
LSP: MS.w95.spi.rsvptcp 
LSP: MS.w95.spi.rsvpudp 


 **** Blocked Control Panel Items ****

BLOCKED: []  


 **** Downloaded Program Files ****

Microsoft XML Parser for Java [file://C:\WINDOWS\Java\classes\xmldso.cab] 
DirectAnimation Java Classes [file://C:\WINDOWS\SYSTEM\dajava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 
Internet Explorer Classes for Java [file://C:\WINDOWS\SYSTEM\iejava.cab] 


 **** Windows Services ****



 **** Custom IE Search Items ****

SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm 


 **** Complete IE Options ****

IEOPT: [Anchor Underline] yes 
IEOPT: [Cache_Update_Frequency] Once_Per_Session 
IEOPT: [Display Inline Images] yes 
IEOPT: [Do404Search]  
IEOPT: [Local Page] C:\WINDOWS\SYSTEM\blank.htm 
IEOPT: [Save_Session_History_On_Exit] no 
IEOPT: [Show_FullURL] no 
IEOPT: [Show_StatusBar] yes 
IEOPT: [Show_ToolBar] yes 
IEOPT: [Show_URLinStatusBar] yes 
IEOPT: [Show_URLToolBar] yes 
IEOPT: [Use_DlgBox_Colors] yes 
IEOPT: [Show_ChannelBand] no 
IEOPT: [Use FormSuggest] no 
IEOPT: [FormSuggest Passwords] yes 
IEOPT: [FormSuggest PW Ask] no 
IEOPT: [Window Title] Microsoft Internet Explorer provided by BROADBAND 
IEOPT: [FullScreen] no 
IEOPT: [check_associations]  
IEOPT: [NotifyDownloadComplete] no 
IEOPT: [LastCheckedHi]  
IEOPT: [Window_Placement] , 
IEOPT: [Disable Script Debugger] yes 
IEOPT: [AddToFavoritesExpanded]  
IEOPT: [Error Dlg Displayed On Every Error] no 
IEOPT: [Error Dlg Details Pane Open] no 
IEOPT: [AutoSearch]  
IEOPT: [Expand Alt Text] no 
IEOPT: [Move System Caret] no 
IEOPT: [NoUpdateCheck]  
IEOPT: [NscSingleExpand]  
IEOPT: [NoJITSetup]  
IEOPT: [NoWebJITSetup]  
IEOPT: [Page_Transitions]  
IEOPT: [Force Offscreen Composition]  
IEOPT: [AllowWindowReuse]  
IEOPT: [Friendly http errors] yes 
IEOPT: [ShowGoButton] yes 
IEOPT: [SmoothScroll]  
IEOPT: [Enable AutoImageResize] yes 
IEOPT: [Enable_MyPics_Hoverbar] yes 
IEOPT: [Play_Animations] yes 
IEOPT: [Play_Background_Sounds] yes 
IEOPT: [Display Inline Videos] yes 
IEOPT: [Show image placeholders]  
IEOPT: [Print_Background] no 
IEOPT: [HistoryViewType]  
IEOPT: [Old Start Page] http://www.singnet.com.sg/ 
IEOPT: [Use Search Asst] no 
IEOPT: [Enable_Disk_Cache] yes 
IEOPT: [Cache_Percent_of_Disk]  
IEOPT: [Delete_Temp_Files_On_Exit] yes 
IEOPT: [Local Page] C:\WINDOWS\SYSTEM\blank.htm 
IEOPT: [Anchor_Visitation_Horizon]  
IEOPT: [Use_Async_DNS] yes 
IEOPT: [Placeholder_Width]  
IEOPT: [Placeholder_Height]  
IEOPT: [Wizard_Version] 6.00.2800.1106 
IEOPT: [CompanyName] Microsoft Corporation 
IEOPT: [Custom_Key] MICROSO 
IEOPT: [Window Title] Microsoft Internet Explorer provided by BROADBAND 
IEOPT: [BigBitmap] C:\PROGRA~1\INTERN~1\Signup\38x38.bmp 
IEOPT: [SmallBitmap] C:\PROGRA~1\INTERN~1\Signup\22x22.bmp 
IEOPT: [FullScreen] no 
IEOPT: [Use Search Asst] no 

Logfile of HijackThis v1.99.1
Scan saved at 11:00:10 PM, on 8/28/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\MY DOCUMENTS\MALWARE_SPYWARECSWTOOLS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =  
R3 - Default URLSearchHook is missing
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab

I hope i did the step in the correct manner as you instructed…

My Firewall still disables itself automatically after startup has finished and windows seems to run something behind which makes the mouse cursor movement slow and dragging after startup.
Close all programs leaving only HijackThis running. Place a check against each of the following,

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - Default URLSearchHook is missing


Click on Fix Checked when finished and exit HijackThis.



Download and install this disk cleanup utility called Cleanup!
Alternate download link.
It will get rid of any malware which may be hiding in your temp folders.
You will also regain a massive amount of disk space.
Here is a tutorial which describes its usage.
I've checked the the ones which you have instructed and click fix.All this was done in Safe Mode.I also have downloaded the CleanUp! and run it according to your tutorial.It clean up and free some 200+Mb from the HDD though…
So here's the new Hijack This log:
Logfile of HijackThis v1.99.1
Scan saved at 12:10:03 AM, on 8/29/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\MY DOCUMENTS\MALWARE_SPYWARECSWTOOLS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =  
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab


The McAfee firewall still disables itself after startup and the cursor moves slowly after startup as i described in my post earlier.Other than that it seems that the generating Malware is gone… :)
Please RIGHT-CLICK HERE and Save As (in IE it's "Save Target As") to download Silent Runners.
  • Save it to the desktop.
  • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
  • You will see a text file appear on the desktop - it's not done, let it run (it won't appear to be doing anything!)
  • Once you receive the prompt "All Done!", double-click the new text file on the desktop, copy that entire log, and paste it here.
*NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
Ok i have downloaded the SilentRunners from the hyperlink and saved it to my desktop.The thing is after i've double-click on it,windows prompt it to be opened by Wordpad…. :huh: .. I waited for quite awhile waiting for a text file to appear on the desktop but it didnt happened.All that happened was the opened Wordpad with some script on it title SilentRunners.vbs. I runned it in the Safe Mode too…and same results.Am i doing it rite??Sorry dude… :( Oh darn :o !!!Now latest update is a worm named "Mad.exe" has been detected by Virus Scan going thru the HDD….deleted from one folder to another by Virus Scan.I wonder whats wrong now….
Errr…sorry for being such a n00b here :oops: .Ok i've downloaded the SilentRunners and its on the desktop,next i've downloaded the Quickzip and already installed it…but how is it possible for the Quickzip to extract the SilentRunners files?? The SilentRunner extension is .vbs and i cant find an option to open the kind of files….i hope you can enllighten this for me.Sorry for being such an a**…. :oops: ….
Double click on the file when quickzip opens highlight the file on the left side then click extract, extract to desk top the click extract again.
Ok i really tried to do what you tell me here…..but is this what you instruct me to do??
[external image: Posted Image]

The problem is i cant seem to be able to extract it… :oops: …..and everytime i double click on the SilentRunners is will open a WordPad with alot of script written on it….. :( like the one below….
[external image: Posted Image]

Well i'm really lost…. :(

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI