As a result... TROJ_MESPAM.AE Alias:Email-Worm.Win32.Warezov.dq (Kaspersky), Spam-Mespam (McAfee), Trojan Horse (Symantec), TR/Spy.BZub.B (Avira), Troj/SpamToo-AO (Sophos),Description:This malware has been renamed to TROJ_MULP.AT. Cookiegal, Jul 25, 2004 #4 ebn Thread Starter Joined: Jul 24, 2004 Messages: 20 cheers!

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocach...etup1.0.0.6.cab O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader

First in the main window look in the bottom right-hand corner and click on Check for updates now and download the latest reference files. Click online, Search for updates, Download all available updates.

Make sure the following settings are made and on -------ON=GREEN From main window: Click Start then Activate in-depth scan (recommended) Click Use custom scanning options then click Customize and have these Cookiegal, Jul 25, 2004 #2 ebn Thread Starter Joined: Jul 24, 2004 Messages: 20 cheers!

It will generate a log.txt file. Under Scanning engine select Unload recognized processes during scanning and under Cleaning Engine select Let windows remove files in use at next reboot Click proceed to save your settings.

Click on "Edit" – "Select all" – "copy" and then "paste" into the thread. Logfile of HijackThis v1.98.0 Scan saved at 01:08:20, on 26/07/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe ebn ebn, Jul 25, 2004 #1 Sponsor Cookiegal Administrator Malware Specialist Coordinator Joined: Aug 27, 2003 Messages: 105,594 Please do this.

fantastic! have a peek at these guys Wintro Wintro 1.0 Witch Control 2004 WLF Trojan WowHack Wukaz 1.03 X RAT X RAT 1.0 X RAT 2.0 XConsole beta Xot 0.5 Beta2 XQ 0.998 YXNetScreen ZZ 2.0 Mise à WORM_RBOT.IT Alias:Packed.Win32.PolyCrypt.b (Kaspersky), W32/Opanki.gen (McAfee), W32.Spybot.Worm (Symantec), TR/Crypt.FKM.Gen (Avira), Mal/HckPk-A (Sophos), Backdoor:Win32/Rbot (Microsoft)Description:Like most RBOT... TROJ_CONHOOK.EY Alias:TR/Dldr.ConHook.Gen (Avira), Troj/Virtum-Gen (Sophos),Description:This malware has been renamed to TROJ_VUNDO.BBT.

here's the log - Logfile of HijackThis v1.98.0 Scan saved at 23:43:04, on 25/07/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe

now, i have seen no evidence of the virus.

http://www.microsoft.com/windowsxp/using/setup/learnmore/tips/kimsey1.mspx I also recommend downloading SPYWAREBLASTER & SPYWAREGUARD, for added protection.

Stay logged in Sign up now!