This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My PC is infected...

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yes the SilentRunners.vbs is already on the desktop.The thing is that when i doule click on it, it doesnt turn out like the one you explained to me.After double-clicking on the file which is on the desktop,i get this windows prompt:

[external image: Posted Image]

And if i cllick yes the wordpad will open like this one below:

[external image: Posted Image]

It doesnt really create a txt file on the desktop and the "All Done" prompt….am i doing it correctly?? :oops:
Here's the report from the SB Search & Destroy:
— Search result list —
Congratulations!: No immediate threats were found. ()
  


— Spybot - Search & Destroy version: 1.4  (build: 20050523) —

2005-08-27 unins000.exe (51.41.0.0)
2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2005-05-31 Update.exe (1.4.0.0)
2005-05-31 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2005-05-31 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2005-04-26 Includes\Cookies.sbi (*)
2005-08-26 Includes\Dialer.sbi (*)
2005-08-26 Includes\Hijackers.sbi (*)
2005-08-16 Includes\Keyloggers.sbi (*)
2005-08-26 Includes\Malware.sbi (*)
2005-04-27 Includes\Revision.sbi (*)
2005-08-25 Includes\Security.sbi (*)
2005-08-16 Includes\Spybots.sbi (*)
2005-08-26 Includes\Trojans.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2005-02-17 Includes\Tracks.uti
2005-08-12 Includes\PUPS.sbi (*)



— System information —
Windows 98 (Build: 2222)  A 
 / MSXML4: Patch Available For XMLHTTP Vulnerability
 / Windows Media Player: Windows Media Update 819639
 / Windows Media Player: Windows Media Update 837272
 / DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution


— Startup entries list —
Located: HK_LM:Run, EnsoniqMixer
command: starter.exe
   file: C:\WINDOWS\starter.exe
   size: 32768
    MD5: 768978e0a8cf41212bbb87edf8d3a070

Located: HK_LM:Run, Icon Animation
command: C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
   file: 

Located: HK_LM:Run, LoadPowerProfile
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
   file: C:\WINDOWS\Rundll32.exe
   size: 24576
    MD5: 3857d93aa630abbd63467db4aeffce2c

Located: HK_LM:Run, LoadQM
command: loadqm.exe
   file: C:\WINDOWS\loadqm.exe
   size: 7536
    MD5: 69d7217f9d7f49d6706baf90f52b472b

Located: HK_LM:Run, MCAgentExe
command: C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
   file: C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
   size: 278528
    MD5: c9a041d6e5211ca48aeba3ac1987d837

Located: HK_LM:Run, MCUpdateExe
command: C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
   file: C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
   size: 180224
    MD5: c7d0c96ad30cfafc37f621c75fad6252

Located: HK_LM:Run, NB Common Dialog Enhancements
command: C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
   file: C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
   size: 22528
    MD5: 44fbbbb26cd1a4751637e5187186a28d

Located: HK_LM:Run, QuickTime Task
command: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
   file: C:\WINDOWS\SYSTEM\QTTASK.EXE
   size: 98304
    MD5: 76a3a30b58405c2c6d833895253a51a9

Located: HK_LM:Run, Start Menu Enhancements
command: C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
   file: C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
   size: 23552
    MD5: 089ad83924668509de862f2b738bf031

Located: HK_LM:Run, SystemTray
command: SysTray.Exe
   file: C:\WINDOWS\SYSTEM\SysTray.Exe
   size: 32768
    MD5: 73681085dcd0997e531240100ca12b28

Located: HK_LM:Run, VirusScan Online
command: "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
   file: C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe
   size: 196608
    MD5: 944982c9b57c8bcc58f4001a62cd503f

Located: HK_LM:Run, VSOCheckTask
command: "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
   file: C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE
   size: 143360
    MD5: d527afe3bed159802f84fee4118b995a

Located: HK_LM:RunServices, McVsRte
command: C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
   file: C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe
   size: 131072
    MD5: d40357f1ba41905355b599228357495d

Located: HK_LM:Run, APPQT32.EXE (DISABLED)
command: C:\WINDOWS\APPQT32.EXE
   file: 

Located: HK_LM:Run, CHotKey (DISABLED)
command: mk9885.exe
   file: C:\WINDOWS\mk9885.exe
   size: 520192
    MD5: f1ad47d71d77ee08797cfaca41850c6b

Located: HK_LM:Run, DataLayer (DISABLED)
command: C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
   file: C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
   size: 999424
    MD5: e404dc8ac66f6ec1baba05e0a4b0f220

Located: HK_LM:Run, FastStart (DISABLED)
command: C:\WINDOWS\system32\svcnut.exe home
   file: 

Located: HK_LM:Run, IEXPLORE.EXE (DISABLED)
command: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
   file: C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
   size: 91136
    MD5: eb9eaf627f705525d01de5fa07ea1818

Located: HK_LM:Run, intell32.exe (DISABLED)
command: C:\WINDOWS\SYSTEM\intell32.exe
   file: 

Located: HK_LM:Run, MCUpdateExe (DISABLED)
command: C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
   file: C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
   size: 180224
    MD5: c7d0c96ad30cfafc37f621c75fad6252

Located: HK_LM:Run, MediaFace Integration (DISABLED)
command: C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
   file: C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
   size: 53248
    MD5: c108e71530073dda128b9998be00acf9

Located: HK_LM:Run, MPFExe (DISABLED)
command: C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
   file: C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
   size: 950272
    MD5: c14da446ebbd90e15fb617bc70e0ebd8

Located: HK_LM:Run, NETYZ.EXE (DISABLED)
command: C:\WINDOWS\SYSTEM\NETYZ.EXE
   file: 

Located: HK_LM:Run, Nokia Tray Application (DISABLED)
command: C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
   file: C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
   size: 425984
    MD5: 224f8afa7840feffc14d755728342664

Located: HK_LM:Run, Oil Change (DISABLED)
command: C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe Start
   file: C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe
   size: 67072
    MD5: 6d1b9f473bbb9a470bfad7398f245eb4

Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
   file: C:\WINDOWS\SYSTEM\QTTASK.EXE
   size: 98304
    MD5: 76a3a30b58405c2c6d833895253a51a9

Located: HK_LM:Run, SAHBundle (DISABLED)
command: C:\WINDOWS\TEMP\bundle.exe
   file: 

Located: HK_LM:Run, TaskMonitor (DISABLED)
command: C:\WINDOWS\taskmon.exe
   file: C:\WINDOWS\taskmon.exe
   size: 28672
    MD5: f795110611101279aa15997801abaca0

Located: HK_LM:Run, TkBellExe (DISABLED)
command: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
   file: C:\Program Files\Common Files\Real\Update_OB\realsched.exe
   size: 180269
    MD5: f9b47f830dd55fedd6ef27d063c29a42

Located: HK_LM:Run, WebRebates0 (DISABLED)
command: "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"
   file: 

Located: HK_LM:Run, WINBR32.EXE (DISABLED)
command: C:\WINDOWS\WINBR32.EXE
   file: 

Located: HK_LM:RunServices, APIWP.EXE (DISABLED)
command: C:\WINDOWS\APIWP.EXE /s
   file: 

Located: HK_LM:RunServices, D3TX.EXE (DISABLED)
command: C:\WINDOWS\D3TX.EXE /s
   file: 

Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
   file: C:\WINDOWS\Rundll32.exe
   size: 24576
    MD5: 3857d93aa630abbd63467db4aeffce2c

Located: HK_CU:Run, Cotr (DISABLED)
command: C:\WINDOWS\Application Data\apac.exe
   file: 

Located: HK_CU:Run, McAfee.InstantUpdate.Monitor (DISABLED)
command: "C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RuLaunch.exe" /STARTMONITOR
   file: 

Located: HK_CU:Run, MSKAGENTEXE (DISABLED)
command: C:\PROGRA~1\MCAFEE\SPAMKI~1\MSKAGENT.EXE
   file: 

Located: HK_CU:Run, MsnMsgr (DISABLED)
command: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
   file: C:\Program Files\MSN Messenger\MsnMsgr.Exe
   size: 4886528
    MD5: 0825fb5b6294e751ffa3d90bbf641cdb

Located: Startup (user), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office\OSA9.EXE
   file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
   size: 65588
    MD5: a89d195caf6a030b152e2a4cabe7018d

Located: Startup (user), Trashgrd.lnk
command: C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
   file: C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
   size: 87040
    MD5: d0bb4024bf4292f6c3929c499ce3c19e



— Browser helper object list —


— ActiveX list —
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
          DPF name: Microsoft XML Parser for Java
        CLSID name: 
         Installer: 
          Codebase: file://C:\WINDOWS\Java\classes\xmldso.cab
       description: 
    classification: Legitimate
    known filename: %WINDIR%\Java\classes\xmldso.cab
         info link: 
       info source: Patrick M. Kolla

DirectAnimation Java Classes (DirectAnimation Java Classes)
          DPF name: DirectAnimation Java Classes
        CLSID name: 
         Installer: 
          Codebase: file://C:\WINDOWS\SYSTEM\dajava.cab
       description: 
    classification: Legitimate
    known filename: %WINDIR%\Java\classes\dajava.cab
         info link: 
       info source: Patrick M. Kolla

Internet Explorer Classes for Java (Internet Explorer Classes for Java)
          DPF name: Internet Explorer Classes for Java
        CLSID name: 
         Installer: 
          Codebase: file://C:\WINDOWS\SYSTEM\iejava.cab
       description: 
    classification: Legitimate
    known filename: %WINDIR%\Java\classes\iejava.cab
         info link: 
       info source: Patrick M. Kolla

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class)
          DPF name: 
        CLSID name: McAfee.com Operating System Class
         Installer: C:\WINDOWS\Downloaded Program Files\mcinsctl.inf
          Codebase: http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
       description: 
    classification: Open for discussion
    known filename: mcinsctl.dll
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\SYSTEM\
         Long name:       MCINSCTL.DLL
        Short name:                   
    Date (created):  6/9/04 6:24:10 PM
Date (last access):            8/31/05
 Date (last write):  3/7/05 3:05:30 PM
          Filesize:             341568
        Attributes:                   
               MD5: E87BA172619E82572106B008BB494B38
             CRC32:           96945A8E
           Version:           4.0.0.90

{BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class)
          DPF name: 
        CLSID name: DwnldGroupMgr Class
         Installer: C:\WINDOWS\Downloaded Program Files\McGDMgr.inf
          Codebase: http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
       description: 
    classification: Open for discussion
    known filename: McGDMgr.dll
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\SYSTEM\
         Long name:        McGDMgr.dll
        Short name:        MCGDMGR.DLL
    Date (created): 6/14/04 5:02:08 PM
Date (last access):            8/31/05
 Date (last write): 2/15/05 11:34:18 AM
          Filesize:             277616
        Attributes:                   
               MD5: 1D9A1D29A60BFB9B92E36E17F0D951E5
             CRC32:           EEB52960
           Version:           1.0.0.23

{9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class)
          DPF name: 
        CLSID name: Update Class
         Installer: C:\WINDOWS\Downloaded Program Files\iuctl.inf
          Codebase: http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?38141.0969444444
       description: Windows Update
    classification: Legitimate
    known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
         info link: 
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\SYSTEM\
         Long name:          iuctl.dll
        Short name:          IUCTL.DLL
    Date (created): 8/21/03 4:47:54 PM
Date (last access):            8/31/05
 Date (last write): 8/21/03 4:47:54 PM
          Filesize:             162400
        Attributes:                   
               MD5: DB2F1F57D3057FEBC19C61AB9AA77198
             CRC32:           5A03D776
           Version:        5.3.3790.13

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
          DPF name: 
        CLSID name: Shockwave Flash Object
         Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
          Codebase: http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
       description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename: 
         info link: 
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\SYSTEM\MACROMED\FLASH\
         Long name:          Flash.ocx
        Short name:          FLASH.OCX
    Date (created):  4/8/04 5:51:02 PM
Date (last access):            8/31/05
 Date (last write):  4/8/04 5:51:02 PM
          Filesize:             939368
        Attributes:                   
               MD5: 2FB1D6FAB135CEE391AB3D70E1C26347
             CRC32:           488FA4EC
           Version:           7.0.19.0

{62475759-9E84-458E-A1AB-5D2C442ADFDE} ()
          DPF name: 
        CLSID name: 
         Installer: 
          Codebase: http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
       description: 
    classification: Open for discussion
    known filename: 
         info link: 
       info source: Safer Networking Ltd.

{166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
          DPF name: 
        CLSID name: Shockwave ActiveX Control
         Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
          Codebase: http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
       description: Macromedia ShockWave Flash Player 7
    classification: Legitimate
    known filename: SWDIR.DLL
         info link: 
       info source: Patrick M. Kolla
              Path: C:\WINDOWS\SYSTEM\MACROMED\DIRECTOR\
         Long name:          SWDIR.DLL
        Short name:                   
    Date (created): 7/15/04 12:51:36 AM
Date (last access):            8/31/05
 Date (last write): 5/28/04 1:38:00 AM
          Filesize:              54480
        Attributes:           archive 
               MD5: 408F53722D9C1280BF4EDD70341EA7F2
             CRC32:           4EB8819E
           Version:           10.0.1.4

{CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
          DPF name: Java Runtime Environment 1.4.2
        CLSID name: Java Plug-in 1.4.2_06
         Installer: 
          Codebase: http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
       description: 
    classification: Legitimate
    known filename: NPJPI142_06.dll
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\Program Files\Java\j2re1.4.2_06\bin\
         Long name:    NPJPI142_06.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 9/28/04 8:26:10 PM
Date (last access):            8/31/05
 Date (last write): 9/28/04 8:26:00 PM
          Filesize:              65650
        Attributes:           archive 
               MD5: 69E5147BA901A9238C4EB08C84E1A85B
             CRC32:           6CB34BCC
           Version:           1.4.2.60

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2)
          DPF name: Java Runtime Environment 1.4.2
        CLSID name: Java Plug-in 1.4.2_06
         Installer: 
          Codebase: http://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab
       description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
         info link: 
       info source: Patrick M. Kolla
              Path: C:\Program Files\Java\j2re1.4.2_06\bin\
         Long name:    NPJPI142_06.dll
        Short name:       NPJPI1~1.DLL
    Date (created): 9/28/04 8:26:10 PM
Date (last access):            8/31/05
 Date (last write): 9/28/04 8:26:00 PM
          Filesize:              65650
        Attributes:           archive 
               MD5: 69E5147BA901A9238C4EB08C84E1A85B
             CRC32:           6CB34BCC
           Version:           1.4.2.60

{41564D57-9980-0010-8000-00AA00389B71} ()
          DPF name: 
        CLSID name: 
         Installer: C:\WINDOWS\Downloaded Program Files\wmvadvd.inf
          Codebase: http://download.microsoft.com/download/0/A/9/0A9F8B32-9F8C-4D74-A130-E4CAB36EB01F/wmvadvd.cab
       description: 
    classification: Legitimate
    known filename: 
         info link: 
       info source: Safer Networking Ltd.

{1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class)
          DPF name: 
        CLSID name: iNotes Class
         Installer: C:\WINDOWS\Downloaded Program Files\inotes.inf
          Codebase: https://iaccess.singaporepower.com.sg/iNotes.cab
       description: 
    classification: Open for discussion
    known filename: inotes.dll
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
         Long name:         inotes.dll
        Short name:         INOTES.DLL
    Date (created): 1/22/04 10:42:02 AM
Date (last access):            8/31/05
 Date (last write): 1/22/04 10:42:02 AM
          Filesize:             344064
        Attributes:                   
               MD5: 39B01D180069FEB904C62608AEEB1E73
             CRC32:           D5040847
           Version:            5.0.8.0

{3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class)
          DPF name: 
        CLSID name: iNotes6 Class
         Installer: C:\WINDOWS\Downloaded Program Files\inotes6.inf
          Codebase: https://iaccess.singaporepower.com.sg/iNotes6.cab
              Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
         Long name:        inotes6.dll
        Short name:        INOTES6.DLL
    Date (created):  2/2/05 1:17:46 PM
Date (last access):            8/31/05
 Date (last write):  2/2/05 1:17:46 PM
          Filesize:             262144
        Attributes:                   
               MD5: 4431773DB91E2B808575ACD6627B6EE1
             CRC32:           68D0F0F3
           Version:           6.0.36.0

{0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class)
          DPF name: 
        CLSID name: DjVuCtl Class
         Installer: C:\WINDOWS\Downloaded Program Files\DjVuLite.inf
          Codebase: http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
       description: 
    classification: Open for discussion
    known filename: DjVuCntl.dll
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\PROGRAM FILES\LIZARDTECH\DJVUCONTROL\
         Long name:       DjVuCntl.dll
        Short name:       DJVUCNTL.DLL
    Date (created): 11/24/03 11:52:28 PM
Date (last access):            8/31/05
 Date (last write): 11/24/03 11:52:28 PM
          Filesize:             184320
        Attributes:                   
               MD5: FEA64B426D4AE07E1ADAC83DB86970B9
             CRC32:           C3C7E916
           Version:          4.5.0.493

{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class)
          DPF name: 
        CLSID name: ActiveScan Installer Class
         Installer: C:\WINDOWS\Downloaded Program Files\asinst.inf
          Codebase: http://www.pandasoftware.com/activescan/as5free/asinst.cab
       description: 
    classification: Open for discussion
    known filename: ASINST.DLL
         info link: 
       info source: Safer Networking Ltd.
              Path: C:\WINDOWS\DOWNLOADED PROGRAM FILES\
         Long name:         asinst.dll
        Short name:         ASINST.DLL
    Date (created):  8/1/05 8:16:40 AM
Date (last access):            8/31/05
 Date (last write):  8/1/05 8:16:40 AM
          Filesize:             135168
        Attributes:                   
               MD5: 48940CD1925A3616B8002B42540CD64C
             CRC32:           1CF9E9D6
           Version:           57.8.0.0



— Process list —
PID: -3208051 (2117021313) C:\WINDOWS\SYSTEM\KERNEL32.DLL
 size: 471040
  MD5: 375B0813980AE17DCC689E913AB9DD7B
PID: -45903 (-3208051) C:\WINDOWS\SYSTEM\MSGSRV32.EXE
 size: 11920
  MD5: 15020A139F22CDBF9C70AA8D80F6AE0E
PID: -48863 (-45903) C:\WINDOWS\SYSTEM\MPREXE.EXE
 size: 28672
  MD5: 562D04789250A81CE629D60646A0D191
PID: -19591 (-48863) C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
 size: 131072
  MD5: D40357F1BA41905355B599228357495D
PID: -117831 (-45903) C:\WINDOWS\SYSTEM\mmtask.tsk
 size: 1184
  MD5: 38BAE36E67C8B1AE3ABC077837953B89
PID: -126843 (-45903) C:\WINDOWS\EXPLORER.EXE
 size: 180224
  MD5: B22B28F61B1BB06723019307F0FAACFC
PID: -183703 (-126843) C:\WINDOWS\SYSTEM\SYSTRAY.EXE
 size: 32768
  MD5: 73681085DCD0997E531240100CA12B28
PID: -182931 (-126843) C:\WINDOWS\STARTER.EXE
 size: 32768
  MD5: 768978E0A8CF41212BBB87EDF8D3A070
PID: -165339 (-126843) C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
 size: 22528
  MD5: 44FBBBB26CD1A4751637E5187186A28D
PID: -172407 (-126843) C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
 size: 23552
  MD5: 089AD83924668509DE862F2B738BF031
PID: -151999 (-126843) C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
 size: 30208
  MD5: 316A663521285A04FDD612C0D6D98610
PID: -137019 (-126843) C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
 size: 196608
  MD5: 944982C9B57C8BCC58F4001A62CD503F
PID: -164163 (-126843) C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
 size: 278528
  MD5: C9A041D6E5211CA48AEBA3AC1987D837
PID: -142467 (-126843) C:\WINDOWS\LOADQM.EXE
 size: 7536
  MD5: 69D7217F9D7F49D6706BAF90F52B472B
PID: -246287 (-137019) C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
 size: 471097
  MD5: C9AE1C7570883EED7F6F81B7AC9ECFF7
PID: -207763 (-140863) C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
 size: 3072
  MD5: 563FEF2236A4DE67E265547F5C75F9AD
PID: -285763 (-183703) C:\WINDOWS\SYSTEM\WMIEXE.EXE
 size: 16384
  MD5: 3DFE9CA6728C02CCD8309DC66B1DFEB1
PID: -232099 (-126843) C:\PROGRAM FILES\SPYBOT - SEARCH & DESTROY\SPYBOTSD.EXE
 size: 4393096
  MD5: 09CA174A605B480318731E691DC98539
PID: -451959 (-164163) C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
 size: 495616
  MD5: D775AB6EE4BC657ADF0F7C90C5FC282D
PID: -334291 (-126843) C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
 size: 91136
  MD5: EB9EAF627F705525D01DE5FA07EA1818
PID: -638023 (-510259) C:\WINDOWS\SYSTEM\DDHELP.EXE
 size: 32768
  MD5: 0B59A22EEA45A9032A3C4ECA40D3BA93


— Browser start & search pages list —
Spybot - Search & Destroy browser pages report, 8/31/05 11:43:22 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
  C:\WINDOWS\SYSTEM\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
  C:\WINDOWS\SYSTEM\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
  http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
  http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


— Winsock Layered Service Provider list —
Protocol  0: MS.w95.spi.osp
        GUID: {FF017DE1-CAE9-11CF-8A99-00AA0062C609}
    Filename: C:\WINDOWS\SYSTEM\mswsosp.dll
 Description: Microsoft Windows 9x/ME name space provider
 DB filename: %windir%\system\mswsosp.dll
 DB protocol: MS.w95.spi.*

Protocol  1: MS.w95.spi.tcp
        GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
    Filename: C:\WINDOWS\SYSTEM\msafd.dll
 Description: Microsoft Windows 9x/ME network protocol
 DB filename: %windir%\system\msafd.dll
 DB protocol: MS.w95.spi.*

Protocol  2: MS.w95.spi.udp
        GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
    Filename: C:\WINDOWS\SYSTEM\msafd.dll
 Description: Microsoft Windows 9x/ME network protocol
 DB filename: %windir%\system\msafd.dll
 DB protocol: MS.w95.spi.*

Protocol  3: MS.w95.spi.raw
        GUID: {FF017DE0-CAE9-11CF-8A99-00AA0062C609}
    Filename: C:\WINDOWS\SYSTEM\msafd.dll
 Description: Microsoft Windows 9x/ME network protocol
 DB filename: %windir%\system\msafd.dll
 DB protocol: MS.w95.spi.*

Protocol  4: MS.w95.spi.rsvptcp
        GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
    Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
 Description: Microsoft Windows 9x/ME network protocol
 DB filename: %windir%\system\rsvoso.dll
 DB protocol: MS.w95.spi.*

Protocol  5: MS.w95.spi.rsvpudp
        GUID: {ECBDCBA0-334A-11D0-BD88-0000C082E69A}
    Filename: C:\WINDOWS\SYSTEM\rsvpsp.dll
 Description: Microsoft Windows 9x/ME network protocol
 DB filename: %windir%\system\rsvoso.dll
 DB protocol: MS.w95.spi.*

Namespace Provider  0: DNS Name Space Provider.
        GUID: {FF017DE2-CAE9-11CF-8A99-00AA0062C609}
    Filename: C:\WINDOWS\SYSTEM\rnr20.dll
 Description: Microsoft Windows 9x/ME name space provider
 DB filename: %windir%\system\rnr20.dll
 DB protocol: DNS Name Space Provider.



— Uninstall list —
Azureus [removed] (Azureus)
install location: C:\Program Files\Azureus
   uninstall cmd: C:\Program Files\Azureus\Uninstall.exe

mIRC  (mIRC)
   uninstall cmd: "C:\PROGRAM FILES\MIRC\MIRC.EXE" -uninstall

Microsoft Office 2000 Standard 9.00.2720 ({00020409-78E1-11D2-B60F-006097C998E7})
         version: 150997664
 version (major): 9
  estimated size: 55143
    install date: 20050419
  install source: F:\
   uninstall cmd: MsiExec.exe /I{00020409-78E1-11D2-B60F-006097C998E7}
       publisher: Microsoft Corporation
       help link: http://www.microsoft.com/support
          readme:  ofread9.txt 

Microsoft NetMeeting 2.11  (NetMeeting)
   uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Remove.W95

Microsoft Web Publishing Wizard 1.6  (WebPost)
   uninstall cmd: RunDll32 ADVPACK.DLL,LaunchINFSection C:\WINDOWS\INF\wpie5x86.inf,WebPostUninstall

  (ADIELangPack)
   uninstall cmd: RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\AD.inf, Uninstall

BitTorrent 3.4.2  (BitTorrent)
   uninstall cmd: "C:\Program Files\BitTorrent\uninstall.exe"

BitTornado 0.2.0 0.2.0 (BitTornado)
   uninstall cmd: C:\Program Files\BitTornado\uninst.exe
       publisher: John Hoffman

  (VGX)

  (DjVu)

RealPlayer  (RealPlayer 6.0)
   uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

  (RealJukebox 1.0)
   uninstall cmd: C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0

GIF Construction Set Professional  (GIF Construction Set Professional)
   uninstall cmd: C:\WINDOWS\ALCHUNIN.EXE C:\Program Files\Alchemy Mindworks\GIF Construction Set Professional\INSTALLD.TXT

dBpowerAMP Musepack Codec  (dBpowerAMP Musepack Codec)
   uninstall cmd: "C:\WINDOWS\SYSTEM\SpoonUninstall.exe" C:\WINDOWS\SYSTEM\SpoonUninstall-dBpowerAMP Musepack Codec.dat

McAfee VirusScan  (VirusScan Online)
   uninstall cmd: C:\PROGRA~1\MCAFEE.COM\SHARED\mcappins.exe /v=3 /uninstall=1 /appid=vso /interact=1 /script_proactive=0 /start=C:\PROGRA~1\MCAFEE.COM\AGENT\uninst\vsoremui.dll::uninstall.htm

HijackThis 1.99.1 1.99.1 (HijackThis)
   uninstall cmd: C:\MY DOCUMENTS\DOWNLOADED FILES\HijackThis.exe /uninstall
       publisher: Soeperman Enterprises Ltd.

Spybot - Search & Destroy 1.4 1.4 (Spybot - Search & Destroy_is1)
install location: C:\Program Files\Spybot - Search & Destroy\
   uninstall cmd: "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
       publisher: Safer Networking Limited

Ad-Aware SE Personal 1.06 (Ad-Aware SE Personal)
   uninstall cmd: C:\PROGRA~1\LAVASOFT\AD-AWA~2\UNWISE.EXE C:\PROGRA~1\LAVASOFT\AD-AWA~2\INSTALL.LOG
       publisher: Lavasoft
       help link: http://www.lavasoft.com

Panda ActiveScan  (Panda ActiveScan)
   uninstall cmd: C:\WINDOWS\SYSTEM\ASUninst.exe Panda ActiveScan
       publisher: Panda Software S.L.

Quick Zip 4.60.008b  (Quick Zip_is1)
install location: C:\Program Files\QuickZip4\
   uninstall cmd: "C:\Program Files\QuickZip4\unins000.exe"
       publisher: Joseph Leung
       help link: http://www.quickzip.org



— System Services —
Service (registry key): Class
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): VxD
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Winsock
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): WDMFS
  Display name: WDM Windows File System Mapper
    Image path: \SystemRoot\System32\Drivers\wdmfs.sys
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): RemoteAccess
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Arbitrators
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): ACPI
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): USB
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): WinSock2
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): NPSTUB
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): EventLog
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): W3SVC
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): MSNP32
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): ProtectedStorage
         Start: 0
          Type: 0
 Error Control: 0

Service (registry key): Cdr4vsd
         Start: 0
          Type: 0
 Error Control: 0

One odd thing happened,while following the tutorial on downloading the updates and installing it the PC suddenly reboots itself.It happened thrice and all happened while the SB Search was updating.On the fourth effort i disabled the VirusScan and Firewall and finally it dowloaded and finished installation without the PC rebooting out of a sudden.
Any ideas why it happen??
Click start > run > type in msconfig > click the start up tab and make sure all the boxes have a check mark.

Under the general tab there should be a green check mark in Normal start up.


Then post another hijackthis log.
Ok i checked the Normal startup tab and clicked all the boxes in the Startup.Btw some of the .exe's in the Startup i believe are the Malware's .exe.Is there anyway that it can be deleted from the startup selection besides unclick the boxes??

Here's the updated HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 7:37:46 PM, on 9/1/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCUPDATE.EXE
C:\WINDOWS\MK9885.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\NCLTOOLS\NCLTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 5\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\SERVICES\SERVICELAYER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSFTSN.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\MY DOCUMENTS\MALWARE_SPYWARECSWTOOLS\HIJACKTHIS.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = 
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =  
F1 - win.ini: run=hpfsched
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [CHotKey] mk9885.exe
O4 - HKLM\..\Run: [Oil Change] C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe Start
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [SAHBundle] C:\WINDOWS\TEMP\bundle.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [FastStart] C:\WINDOWS\system32\svcnut.exe home
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [WINBR32.EXE] C:\WINDOWS\WINBR32.EXE
O4 - HKLM\..\Run: [NETYZ.EXE] C:\WINDOWS\SYSTEM\NETYZ.EXE
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\Run: [APPQT32.EXE] C:\WINDOWS\APPQT32.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [APIWP.EXE] C:\WINDOWS\APIWP.EXE /s
O4 - HKLM\..\RunServices: [D3TX.EXE] C:\WINDOWS\D3TX.EXE /s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Cotr] C:\WINDOWS\Application Data\apac.exe
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\MCAFEE\SPAMKI~1\MSKAGENT.EXE
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab


Should you need instructions for ;
Showing hidden files and folders in Windows.
Reboot in safe mode.
How to set up a HijackThis folder correctly to make backups.
Scan with Spybot S&D and Ad-Aware
Click the links above.



Please download and install this disk cleanup utility called Cleanup! Don't run it yet.
Alternate download link.
It will get rid of any malware which may be hiding in your temp folders.
You will also regain a massive amount of disk space.
Here is a tutorial which describes its usage.



Please Zip these files and send them here
The following have randomly named file names, and as such are normally malware.
Follow their process tree. Right click on the file and go to Properties.
Then go to the Version tab to see what company name it's from:
If it's from some name you never heard of or if it's blank,
Please check for removal and delete the file in bold also.

O4 - HKLM\..\Run: [WINBR32.EXE] C:\WINDOWS\WINBR32.EXE
O4 - HKLM\..\Run: [NETYZ.EXE] C:\WINDOWS\SYSTEM\NETYZ.EXE
O4 - HKLM\..\Run: [APPQT32.EXE] C:\WINDOWS\APPQT32.EXE
O4 - HKLM\..\RunServices: [APIWP.EXE] C:\WINDOWS\APIWP.EXE
O4 - HKLM\..\RunServices: [D3TX.EXE] C:\WINDOWS\D3TX.EXE
O4 - HKCU\..\Run: [Cotr] C:\WINDOWS\Application Data\apac.exe


Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O4 - HKLM\..\Run: [SAHBundle] C:\WINDOWS\TEMP\bundle.exe
O4 - HKLM\..\Run: [WebRebates0] "C:\PROGRAM FILES\WEB_REBATES\WebRebates0.exe"
O4 - HKLM\..\Run: [FastStart] C:\WINDOWS\system32\svcnut.exe home
O4 - HKLM\..\Run: [intell32.exe] C:\WINDOWS\SYSTEM\intell32.exe

.



Reboot in safe mode.
Then click start>my computer>local disk
(then follow the path) or Using Windows Explorer, locate the following files/folders, and delete them:
Delete the following file(s) listed.
C:\WINDOWS\TEMP\bundle.exe
C:\WINDOWS\system32\svcnut.exe
C:\WINDOWS\SYSTEM\intell32.exe


Delete the folder(s) listed
C:\PROGRAM FILES\WEB_REBATES

Run Cleanup!
Reboot and Rescan with HJT and post a new log here.
Also please describe how your computer behaves now.




If you were unable to find any of the files then please follow these additional instructions:

Download Pocket Killbox and unzip it; save it to your Desktop.

Run it, and click the radio button that says Delete a file on reboot. For each of the files you could not delete, paste them one at a time into the full path of file to delete box and click the red circle with a white cross in it.

The program will ask you if you want to reboot; say No each time until the last one has been pasted in whereupon you should answer Yes.

Let the system reboot.

Please Zip these files and send them here

204443

Pardon me…but which files are you refering to??Do you mean these??
C:\WINDOWS\WINBR32.EXE
C:\WINDOWS\SYSTEM\NETYZ.EXE
C:\WINDOWS\APPQT32.EXE
C:\WINDOWS\APIWP.EXE
C:\WINDOWS\D3TX.EXE
C:\WINDOWS\Application Data\apac.exe

If those are the files you wanted…i'm afraid it has already been deleted by McAfee VirusScan the moment it detected them during the early stage of infection.But scrolling the System folder i found a few which are suspicious and has never heard of:
-addfo32.exe
-apiis.exe
-appag.exe
-appdp.exe
-appha32.exe
-atlad32.exe
-atlig.exe
-atldj32.exe
-atlqq32.exe
-altvx.exe
-cryu32.exe
-d3mw.exe
-d3zx.exe
-ieey.exe
-ieqq32.exe
-ieut32.exe
-iphd.exe
-javaoz.exe
-mshn.exe
-ntqm.exe
-sdkgm.exe
-sdkid32.exe
-sdkxa.exe
-sysmr32.exe
-systx32.exe
-windt.exe
-winfs.exe
-winjb32.exe
-algrm.dll
-javavq32.dll
-asfiles.txt


These files were found in the System folder and all their sizes are 0kB….i've moved them out of the folder and already zipped them.If you want me to email to you just give me the word.

As for these files/folders which you wanted me to delete are also not in the HDD anymore.(Just so you know i've set the file types in Properties to show all the hidden files)
C:\WINDOWS\TEMP\bundle.exe
C:\WINDOWS\system32\svcnut.exe
C:\WINDOWS\SYSTEM\intell32.exe
C:\PROGRAM FILES\WEB_REBATES

Here is the new HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:56:52 PM, on 9/2/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\STARTER.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\COMDLGEX.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\STARTM.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\WINDOWS\LOADQM.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WINDOWS\MK9885.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\NCLTOOLS\NCLTRAY.EXE
C:\WINDOWS\TASKMON.EXE
C:\PROGRAM FILES\NOKIA\NOKIA PC SUITE 5\DATALAYER.EXE
C:\PROGRAM FILES\COMMON FILES\REAL\UPDATE_OB\REALSCHED.EXE
C:\PROGRAM FILES\MCAFEE\OIL CHANGE\SCHEDAPP.EXE
C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\TRASHSRV.EXE
C:\PROGRAM FILES\COMMON FILES\NOKIA\SERVICES\SERVICELAYER.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSFTSN.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\PERSONAL FIREWALL\MPFTRAY.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\MY DOCUMENTS\MALWARE_SPYWARECSWTOOLS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by BROADBAND
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =  
F1 - win.ini: run=hpfsched
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [EnsoniqMixer] starter.exe
O4 - HKLM\..\Run: [NB Common Dialog Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\comdlgex.exe
O4 - HKLM\..\Run: [Start Menu Enhancements] C:\PROGRA~1\MCAFEE\MCAFEE~1\startm.exe
O4 - HKLM\..\Run: [Icon Animation] C:\PROGRAM FILES\MCAFEE\MCAFEE UTILITIES\HDE.EXE /hook
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [CHotKey] mk9885.exe
O4 - HKLM\..\Run: [Oil Change] C:\PROGRA~1\MCAFEE\OILCHA~1\OCTray32.exe Start
O4 - HKLM\..\Run: [Nokia Tray Application] C:\Program Files\Common Files\Nokia\NCLTools\NclTray.exe
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Nokia\Nokia PC Suite 5\DataLayer.exe
O4 - HKLM\..\Run: [MediaFace Integration] C:\Program Files\Fellowes\MediaFACE 4.0\SetHook.exe
O4 - HKLM\..\Run: [IEXPLORE.EXE] C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\MCAFEE.COM\PERSON~1\MPFTRAY.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\PROGRAM FILES\MCAFEE\MCAFEE SHARED COMPONENTS\INSTANT UPDATER\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [MSKAGENTEXE] C:\PROGRA~1\MCAFEE\SPAMKI~1\MSKAGENT.EXE
O4 - Startup: Trashgrd.lnk = C:\Program Files\McAfee\McAfee Utilities\TRASHGRD.exe
O4 - Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040427/qtinstall.info.apple.com/saba/us/win/QuickTimeInstaller.exe
O16 - DPF: {1E2941E3-8E63-11D4-9D5A-00902742D6E0} (iNotes Class) - https://iaccess.singaporepower.com.sg/iNotes.cab
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://iaccess.singaporepower.com.sg/iNotes6.cab
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab

After i have followed the instructions you gave and upon start up….windows load all the programs like IE,MSN Msgr and the others…..so it took some time to really move the mouse.The Firewall is still the same…it disables auto. after startup.
Other than that everything seems normal…

    *  control.exe  << this one might be the trouble

204861


I did as you instructed and followed the link on how to install to the correct directories…
I managed to unzipped and instal the control.exe but as for the others below, they already existed in their respective directories/folder…

    * rundll32.exe
    * wmplayer.exe
    * msconfig.exe
    * notepad.exe
    * shell.dll
    * SDHelper.dll

204861


So whats the next step that i should do??
Ok i tried unstalling the McAfee VirusScan a couple of times but i get a lot of errors and it just wont uninstall…..the file vsoremui.dll(i think) had some errors to it.So i manage to get a hold of the .dll file from http://www.dlldump.com/dll-files/V_4.html and replace the problem one.
I manage to uninstall as you instructed and re-install……the good news is that after updating the Virus .dat files my PC didnt auto shutdown itself and reboot lilke it always did but it prompt me a window to restart the PC which should be the way i believe.
Well now what do i do next, little eagle??
Whoa??!!Everythings fine……. :scratch: …??Woohoo………….!!!Thks little eagle for having the patience and helping me out along the way!!! :thumbup:

Well i think this thread is a wrap…..and i hope everything will turn out sweet.Well once again to you little eagle and the Admins/Moderators of this board in helping troubled PC users like me and the others to utilise as well as helping us.Cheeerss!!!!!!!!!!! ;)
Gald we could help. :D here is the closing speech.

[If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.


To help keep you clean follow the recommendations in Tony's article here:
So how did I get infected in the first place?

Please follow a few tips to remain malware free:

Make sure you keep your Windows OS current by visiting Windows update
occasionaly to download and install any critical updates and service packs. With out these you are leaving the backdoor open.

Also download, install and keep updated- Antivirus Software (and use only one):
Free for home users:
avast! 4 Home Edition Download
AVG free version 7.0 AVG free version v6.0 updates ended 12/31/04
AntiVir Personal Edition

Adjust your browser settings: Change your(active x) settings in IE. With IE open go to tools, internet options, security tab. Click on the internet globe, then custom level. Set the first option "download signed active x controls" to prompt, the next two to disable. Read more:
Internet Explorer Privacy & Security Settings
Working with Internet Explorer 6 Security
Many exploits are directed at Internet Explorer, you dont have to use it. Try a different browser:
Like Firefox,
And Thunderbird for controling spam in your e-mail.

Install a firewall. A firewall will control what comes in from the internet and what leaves your computer to the internet. A firewall will also alert you when a application trys to connect to the internet from your computer, this is a good way to catch crapware or trojans, trying to connect out bound from your computer- whats that and why does it need a internet connection? You can deny it access it until more investigation is done. Zone Alarm is a free and easy to use firewall, that will provide in and outbound protection. Microsoft XP firewall only provides inbound protection, but is not as robust as third party firewalls, Be sure to run only >one< firewall.If you use another, be sure to disable XP's built in firewall.A inexpensive NAT hardware router with SPI (firewall)would be even better,along with a software firewall.
Zone Alarm
Kerio Personal Firewall
Outpost Firewall

Download, install and update before using:(if these are constantly finding malware, then you need to make some changes)
Ad-Aware SE Personal edition
Spybot Search and destroy
Becarful with spyware "removers and scanners"– there are many "rogue/suspect" programs that "claim to remove" spyware.

Other programs to consider:
SpywareBlaster
IE-SPYAD
AntiTrojan software to fill in the gap:
a2 free
Ewido Security Suite
Trojan Hunter (30 day trial version)

Learn More:
Tony's article So how did I get infected in the first place?
How to Secure (and Keep Secure) My (New) Computer(s)
Home Computer Security
Wilders Security Advisors

Watch what you download, and where you download it from.
Many programs come bundled with "extra" crapware you may not want. Make sure you know what it is you will be downloading and installing. Visit the makers website, learn more about the program, Does the program you want come bundled with other "3rd party" programs? What do the 3rd party programs do? Will they deliver ads? Track your surfing habits?.You may be installing more than you think, Read the EULA agreement, you know that paragraph of stuff you "agree to" before the software installs? Stay away from warez and crack sites. Becarful what you download from file sharing networks.If you are not sure, scan it with your Antivirus app. A small file (in KB) is probably not what you think it is. Some p2p clients also install 3rd party stuff you probably dont want.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI