This thread's last reply is from June 17, 2006, 6:22 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Logfile of HijackThis v1.99.1
Scan saved at 22:01:06, on 04/06/2006
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
+ Created on: 21:52:02, 04/06/2006
+ Report-Checksum: A38A9109
+ Scan result:
C:\Documents and Settings\ibm\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ibm\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ibm\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ibm\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\[redacted][2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\[redacted][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\[redacted][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ibm\Cookies\ibm@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ibm\Local Settings\Temp\Cookies\[redacted][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
C:\Documents and Settings\ibm\Local Settings\Temp\Cookies\[redacted][1].txt -> TrackingCookie.Sextracker : Cleaned with backup
C:\Documents and Settings\ibm\Local Settings\Temp\Cookies\[redacted][2].txt -> TrackingCookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\ibm\Local Settings\Temp\Cookies\ibm@sextracker[2].txt -> TrackingCookie.Sextracker : Cleaned with backup
C:\Program Files\Media-Codec -> Trojan.Small : Cleaned with backup
C:\Program Files\Media-Codec\uninst.exe -> Trojan.Small : Cleaned with backup
Scan done at 21:20:21.26, Sun 04/06/2006
Run from C:\Documents and Settings\ibm\Desktop\SmitfraudFix
OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
Run and scan with HijackThis. With all browsers and windows closed, place checks beside the following and fix:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINNT\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
Go here and download and install JRE 5.0 Update 7. Click the link that says Download JRE 5.0 Update 7. You will then need to select Accept License Agreement and click the Continue button that is beside it. Then click the link that says Windows Offline Installation, Multi-language. Save it to your Desktop. Then go back to your Desktop and double click jre-1_5_0_07-windows-i586-p.exe to start the install. Once you have it installed, click Start>Run, type in appwiz.cpl and hit Enter. From the list, uninstall J2SE Runtime Environment 5.0 Update 6.
Logfile of HijackThis v1.99.1
Scan saved at 18:20:52, on 06/06/2006
Platform: Windows 2000 SP3 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Hmmm... never heard of an infection messing with the sound functions on a computer... really isn't much that malware can take advantage of there. And the infections you had aren't known to mess with the sound of a computer anyways... I'm inclined to think its something unrelated to malware.
The slow/no web page loading could be connection issues between you and the webserver(s) of whatever sites you are using.
Gonna get you to do a couple more scans to make sure nothing is lurking about.
Download WinPFind and extract it to your C:\ drive. This will create a folder called WinPFind in the C:\ drive. Inside C:\WinPFind is a file called WinPFind.exe. Double-click on this file to launch the program. Once it is launched, click on the Start Scan button and wait for it to finish. This program will scan large amounts of files on your computer for known patterns so please be patient while it works as it can take a while, upwards to 30 minutes or more. Once its done you can copy/paste the results into a ne notepad document and save it to your Desktop.
i will reply tommorow as i have to go to sleep for work in the morning i will reply here.
✨ Ask AI about this thread
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.