View Single Post
Old 04-17-2006, 06:43 AM   #11 (permalink)
Hustler24
Analyst, Security Team
 
Join Date: Mar 2005
Posts: 890
OS: Windows XP Home


Please uninstall the following from Add/Remove Programs:

Viewpoint Media Player
Java 2 Runtime Environment, SE v1.4.2_06


Download and unzip BFUzip from http://www.merijn.org/files/bfu.zip
Run the program and click the Web button as shown here:


Use this URL to copy into the address bar of the Download script window:
http://metallica.geekstogo.com/alcanshorty.bfu

Execute the script by clicking the Execute button.

If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html


Click Start > Run. Type

Quote:
regsvr32 /u occache.dll


Please delete the following files in red and folders in blue:

C:\WINDOWS\DOWNLOADED PROGRAM FILES\YSBactivex.inf

C:\WINDOWS\newname.dat
C:\PROGRAM FILES\COMMON FILES\Windows
C:\iexplore.exe < - Only from this location
C:\Setup.exe
C:\sk02.exe
C:\WINDOWS\system32\rar.exe

Click Start > Run and type:

Quote:
regsvr32 occache.dll


Perform an online scan with Internet Explorer with

Kaspersky WebScanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will then begin downloading the latest definition files.
  • Once the files have been downloaded click on NEXT
  • Locate the Scan Settings button & configure to:
    • Scan using the following Anti-Virus database:
      • Extended
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK & have it scan My Computer
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan

Post the Kaspersky scan here with another HJT log.

Last edited by Hustler24; 04-17-2006 at 06:44 AM.
Hustler24 is offline