June 6, 2004

Killing the featured-results.com pop-up

This is really depressing. After I delete the suspect files, e.g., inetp60.dll and rundll32.exe. They reappear! Unbelieveable. It is self-healing adware. I finally brokedown and downloaded PestPatrol which, without payment, won't delete anything.

Here's what I found:

1AtlasDMT.com Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@atdmt[2].txt
Tracking URL: atdmt.com
Hits: 3
Received: 6/5/2004 11:08:36 PM
Expires: 6/4/2009 5:00:00 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
2Bluestreak.com Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@bluestreak[1].txt
Tracking URL: bluestreak.com
Hits: 5
Received: 6/6/2004 2:59:32 PM
Expires: 6/4/2014 10:58:48 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
3DoubleClick Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@doubleclick[1].txt
Tracking URL: doubleclick.net
Hits: 10
Received: 6/6/2004 7:53:50 AM
Expires: 6/6/2007 7:53:06 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
4Ehg.Hitbox Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@ehg.hitbox[2].txt
Tracking URL: ehg.hitbox.com
Hits: 2
Received: 6/6/2004 2:54:50 PM
Expires: 6/6/2005 2:54:06 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
5HitBox.com Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@hitbox[2].txt
Tracking URL: hitbox.com
Hits: 5
Received: 6/6/2004 2:54:50 PM
Expires: 6/6/2005 2:54:06 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
6Statcounter Spyware CookieCategory: Spyware Cookie
Background Info: Click here
In File: C:\Documents and Settings\Test\Cookies\test@statcounter[2].txt
Tracking URL: statcounter.com
Hits: 3
Received: 6/6/2004 2:54:36 PM
Expires: 6/5/2009 2:53:12 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete
7AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\clsid\{fac6e0e1-5d45-4907-bc00-302d702dcc73}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
8AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\cpr.iehelperopCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
9AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{91d91d21-8008-429d-821c-7266aac84a9f}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
10AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\typelib\{ace8d3ba-7742-44c4-920d-fd25bd1e8245}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
11AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\clsid\{fac6e0e1-5d45-4907-bc00-302d702dcc73}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
12AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\toolbar|{bdf6ce3d-f5c5-4462-9814-3c8eac330ca8}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
13AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{bdf6ce3d-f5c5-4462-9814-3c8eac330ca8}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
14AdRoarCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{fac6e0e1-5d45-4907-bc00-302d702dcc73}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
15BargainBuddyCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{9d1b86c7-1b93-4586-9009-ea3bd0ad63a5}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
16BargainBuddyCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{b8afa251-4efb-4703-87d4-da7d2435ba5e}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
17BargainBuddyCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{df7d760c-b7e2-4735-bb77-f5a1a9745e16}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
18BrowserAidCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runwindowsupdateCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
19BrowserAid.ABCSearchCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\typelib\{7eb64065-dfd1-41b0-99d7-6ba3e0a15916}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
20BrowserAid.ABCSearchCategory: Adware
Background Info: Click here
In Registry: HKEY_CURRENT_USER\software\popup stopperCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
21BrowserPalCategory: Adware
Background Info: Click here
In Registry: HKEY_CURRENT_USER\software\browser palCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
22BrowserPalCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\browser palCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
23BrowserPalCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{07b7f771-1b8e-4b7b-823e-ffac1732aa9f}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
24DownloadWareCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\btieinscriptconfigproj.btieinscriptconfigCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
25DownloadWareCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\clsid\{26e8361f-bce7-4f75-a347-98c88b418322}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
26DownloadWareCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{26e8361f-bce7-4f75-a347-98c88b418321}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
27DownloadWareCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{26e8361f-bce7-4f75-a347-98c88b418328}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
28DownloadWareCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\typelib\{53f066f0-a4c0-4f46-83eb-2dfd03f938cf}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
29ExactSearchBarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\typelib\{53f066f0-a4c0-4f46-83eb-2dfd03f938cf}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
30Ezula TopTextCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{226a045e-fd4e-4632-b51d-a112bd8254e5}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
31Ezula TopTextCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\classes\interface\{f6fbfe07-ca76-438e-b34e-4f4dc41f0123}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
32FactoryNetwork DialerCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\dksoftwareCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
33Gigatech SuperbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{9d1b86c7-1b93-4586-9009-ea3bd0ad63a5}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
34Gigatech SuperbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{b8afa251-4efb-4703-87d4-da7d2435ba5e}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
35Gigatech SuperbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{df7d760c-b7e2-4735-bb77-f5a1a9745e16}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
36HuntBarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\typelib\{26e8361f-bce7-4f75-a347-98c88b418328}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
37IBIS ToolbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\btieinscriptconfigproj.btieinscriptconfigCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
38IBIS ToolbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\clsid\{26e8361f-bce7-4f75-a347-98c88b418322}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
39IBIS ToolbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{26e8361f-bce7-4f75-a347-98c88b418321}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
40IBIS ToolbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\protocols\handler\relatedlinksCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
41IBIS ToolbarCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\protocols\name-space handler\res\btlink.resprotocolCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
42IGetNetCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{226a045e-fd4e-4632-b51d-a112bd8254e5}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
43IGetNetCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\interface\{f6fbfe07-ca76-438e-b34e-4f4dc41f0123}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
44INetSpeak.IexplorrCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4cebbc6b-5cee-4644-80cf-38980bae93f6}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
45INetSpeak.IexplorrCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6b12dabb-0b7c-44fa-b0b3-4baff3790256}Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
46KaZaACategory: Adware
Background Info: Click here
In Registry: HKEY_CURRENT_USER\software\kazaaCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
47KaZaACategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\kazaaCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
48KaZaACategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\app paths\d:\installshield\kazaaCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
49Marketscore(Netsetter)Category: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\netsetterCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
50SAHAgentCategory: Adware
Background Info: Click here
In Registry: HKEY_LOCAL_MACHINE\software\vgroupCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
51WurldMediaCategory: Adware
Background Info: Click here
In Registry: HKEY_CLASSES_ROOT\tchk.tchkbhoCertainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or ignore
52AdRoarCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\cpr.dll
Date: 12/18/2003 10:26:56 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
53AtomWireCategory: Adware
Background Info: Click here
In File: C:\WINNT\iexplorr23.dll
Date: 4/18/2003 4:32:20 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
54AtomWireCategory: Adware
Background Info: Click here
In File: C:\WINNT\iexplorr24.dll
Date: 4/18/2003 4:32:42 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
55BargainBuddyCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\msbb.dll
Date: 5/5/2003 8:57:50 PM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
56BargainBuddyCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\msbb1.dll
Date: 7/26/2003 7:50:56 AM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
57BargainBuddyCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\mset_bbi8010.dll
Date: 5/8/2003 9:30:54 PM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
58BargainBuddyCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\mset_bbi80101.dll
Date: 7/22/2003 9:29:44 PM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
59BrowserAid.RunDLL16Category: Adware
Background Info: Click here
In File: C:\WINNT\uptodate.exe
Date: 3/25/2003 2:51:10 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
60BrowserAid.SearchandClickCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\inetp60.dll
Date: 2/7/2004 9:38:46 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
61CommonNameCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\winnet.ini
Date: 9/24/2003 9:17:42 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or quarantine
62CydoorCategory: Adware
Background Info: Click here
In File: C:\Documents and Settings\Test\local settings\temp\cd_clint.dll
Date: 1/14/2002 2:57:00 PM
Company Name: Cydoor Technologies, Inc.
File Description: Cydoor Technologies ad-system
File Version: 3, 2, 1, 0
Internal Name: CD_Clint.dll
Legal Copyright: Copyright (C) Cydoor Technologies, Inc. 1999-2001
Original Filename: CD_Clint.dll
Product Name: Cydoor Technologies ad-system
Product Version: 3, 2, 1, 0
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
63ExactSearchBarCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\ezstubi.dll
Date: 6/7/2003 6:34:04 PM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
64Ezula TopTextCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\ezstubtt.exe
Date: 6/7/2003 6:34:04 PM
File Description: LOP Application
File Version: 1, 0, 0, 1
Internal Name: LOP
Legal Copyright: Copyright (C) 2002
Original Filename: LOP.exe
Product Name: LOP Application
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
65FavoriteManCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\mbr32.dll
Date: 5/10/2004 7:37:00 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
66FavoriteManCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\mpz300.dll
Date: 3/5/2003 4:09:58 PM
File Description: F1 - Windows help for smart browsing
File Version: 3, 0, 0, 1
Internal Name: F1
Legal Copyright: Copyright 2001
Original Filename: F1.DLL
Product Name: F1
Product Version: 3, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
67IGetNetCategory: Adware
Background Info: Click here
In File: C:\WINNT\system\update_com.dll
Date: 8/31/2003 11:28:24 AM
Company Name: iGetNet.com
File Description: Natural Language Navigation
File Version: 6.00.0005
Internal Name: Rsp001
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
68IPInsightCategory: Adware
Background Info: Click here
In File: C:\WINNT\sentry.ini
Date: 5/4/2003 1:58:02 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or quarantine
69MSViewCategory: Adware
Background Info: Click here
In File: C:\WINNT\inf\msview.inf
Date: 6/16/2003 1:05:42 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
70MSViewCategory: Adware
Background Info: Click here
In File: C:\WINNT\msvprep.exe
Date: 6/16/2003 1:03:20 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
71NCaseCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\ncmyb.dll
Date: 7/26/2003 7:53:12 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
72NetPalCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\netpals.dll
Date: 8/19/2003 1:54:40 PM
File Description: exe_in_dll Module
File Version: 1, 0, 0, 1
Internal Name: exe_in_dll
Legal Copyright: Copyright 2001
Original Filename: exe_in_dll.DLL
Product Name: exe_in_dll Module
Product Version: 1, 0, 0, 1
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
73NetSetterCategory: Adware
Background Info: Click here
In File: C:\WINNT\system32\csloa.dll
Date: 4/29/2003 10:16:18 PM
Company Name: comScore Inc.
File Description: AOL Adapter
File Version: 3, 0, 5, 41
Internal Name: csloa
Legal Copyright: Copyright 2000
Original Filename: csloa.DLL
Product Name: csloa Module
Product Version: 3, 0, 5, 41
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
74SAHAgentCategory: Adware
Background Info: Click here
In File: C:\WINNT\sahuninstall.exe
Date: 5/6/2003 4:04:42 AM
Company Name: -
File Description: SAHUninstall
File Version: 1, 1, 1, 17
Internal Name: SAHUninstall
Legal Copyright: Copyright © 2002
Original Filename: SAHUninstall.dll
Product Name: - SAHUninstall
Product Version: 1, 1, 1, 17
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
75BrowserAid.ABCSearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Documents and Settings\Test\application data\browser pal
Date: 6/4/2003 5:55:50 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
76BrowserAid.ABCSearch?Category: Adware
Background Info: Click here
In File: C:\Documents and Settings\Test\application data\browser pal\bpcfg.xml
Date: 6/4/2003 5:55:50 PM
Certainty: Suspected
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or quarantine
77BrowserAid.ABCSearch?Category: Adware
Background Info: Click here
In File: C:\Documents and Settings\Test\application data\browser pal\pstopper.sts
Date: 6/4/2003 10:30:12 PM
Certainty: Suspected
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete or quarantine
78ClearSearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Documents and Settings\Test\local settings\temp\clrsch
Date: 6/6/2004 7:53:12 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
79ClearSearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Documents and Settings\Test\locals~1\temp\clrsch
Date: 6/6/2004 7:53:12 AM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
80IBIS Toolbar DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Program Files\common files\btlink
Date: 1/17/2004 7:52:08 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
81Lycos Sidesearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Program Files\lycos
Date: 10/3/2003 9:25:58 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
82Lycos Sidesearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Program Files\lycos\Sidesearch
Date: 12/15/2003 11:15:14 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
83Lycos Sidesearch DirectoryCategory: Adware
Background Info: Click here
In Directory: C:\Program Files\lycos\Sidesearch\temp
Date: 12/16/2003 9:08:22 PM
Certainty: Confirmed
Threatens: Confidentiality, Liability
Risk: Low.
Advice: Delete when empty
84VX2.MSViewCategory: Browser Helper Object
Author: [Mindset Interactive]
Release Date: 1/14/2003 0:00:00
Background Info: Click here
In File: C:\WINNT\LastGood\MSView.DLL
PVT: -122401757
MD5: 9de5c18a4ff98fce9c5da6ead8ec5f1b
Date: 12/14/2002 10:17:32 AM
Company Name: MSView Inc.
File Description: MSView module
File Version: 0, 0, 4, 12
Internal Name: MSView
Legal Copyright: Copyright 2001, 2002
Original Filename: MSView.DLL
Product Name: MSView
Product Version: 0, 0, 4, 12
File Analysis: Look up with MD5 (recommended) or PVT.
Certainty: Confirmed
Threatens: Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine
85ClearSearchCategory: Hijacker
Author: [Clear Search, Inc.]
Release Date: 1/20/2004 0:00:00
Background Info: Click here
In File: C:\WINNT\system32\ClrSchP012.exe
PVT: -1324841362
MD5: c9ca61949a0c9913ccb8883ad095c115
Date: 2/16/2004 9:57:08 PM
Company Name: Clear Search
File Description: Loader
File Version: 1, 0, 0, 3
Internal Name: Loader
Legal Copyright: Copyright © 2003
Original Filename: Loader.exe
Product Name: Loader
Product Version: 1, 0, 0, 3
File Analysis: Look up with MD5 (recommended) or PVT.
Certainty: Confirmed
Threatens: Liability
Risk: Moderate - this file can be executed!
Advice: Delete or quarantine


Depressing.

Posted by torque at June 6, 2004 3:17 PM | TrackBack
Comments

I had that problem too.. you can't delete rundll32.exe ... it's something else (my IT guys got rid of it for me...

Posted by: christine at June 7, 2004 10:21 AM

HijackThis is more difficult to use than AdAware and Spybot Search & Destroy, but many have said it got rid of things the others missed, including myself.
http://www.spywareinfo.com/~merijn/downloads.html

If Hijack This won't run, check out that page's advice for why it won't run (some spywares put anti-spyware code in their programs...that page has fixes for that).

It lists all things running at the time the program's run, and I think it also lists all startup programs from the registry, autoexec.bat, startup folder, ect...

They recommend to just run it to get a list, then post the ENTIRE list, UNedited, to one of the forums in his links list (under a new thread).

After I was hijacked last year, I used Hijack This to get rid of xxxtoolbar, then installed WinPatrol, and quit using IE.
http://www.winpatrol.com/winpatrol.html

They're both free to use; Winpatrol has an advanced program for paying customers.

Posted by: Sherri at June 11, 2004 9:26 PM

RUNDLL32.EXE is a valid Windows file and can't be removed. The inetp60.dll file is being regenerated by whatever program put it there, so you have to find and eliminate that program. Here's a trick I discovered to get rid of suspect programs:

Boot to safe mode. Unhide hidden/system files, and also unhide file extensions. Open Explorer and navigate to the C:\Windows folder. Click the "View" menu then "Arrange icons by > Type."

You'll see all the EXE listed first. As you pass the pointer over each file, you'll see a desrciption of the file. All Windows executables and other companies' valid EXEs will have a description of what the file is. If you only see a date that the file was created, it's a good bet you don't need it, especially if the filename is a jumble of letters. Delete them. NOTE: Some legacy Windows files will only have the date as well, but they go back to 2002 or earlier. Only delete those that are within the past couple months. Those are probably your adware file droppers. Do this in the System32 folder, too.
Then, while still in safe mode, you can access the C:\Recycled folder. Delete everything in there to make sure the files are unrecoverable.

Then hit CTL-ALT-DEL and turn off all processes that are not listed as "SYSTEM." You can now delete the offensive DLLs in the same manner, and they shoudn't come back. It takes some time, but it has been remarkably effective for me.

Posted by: Mark at August 2, 2004 3:07 PM

About your disappearing files (rundll32.exe etc)
If you were to sucessfully delete them, your system would no longer run properly.

inetp60.dll is adware, it's categorized under Adware.BrowserAid. You also must be aware of another file which also is installed with this first file : msiefr40.dll

To remove this run regedit and search for these entries:

HKEY_LOCAL_MACHINE\software\classes\clsid\{087173ef-9829-4f49-8340-a524177d3f60}

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{087173ef-9829-4f49-8340-a524177d3f60}

HKEY_LOCAL_MACHINE\software\classes\clsid\{0ddbb570-0396-44c9-986a-8f6f61a51c2f}

HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{0ddbb570-0396-44c9-986a-8f6f61a51c2f}

HKEY_LOCAL_MACHINE\software\classes\clsid\{606220ae-90e0-41ca-bf6d-c89272ed680c}

Delete them all, reboot then search for and delete these 2 files from your computer :
msiefr40.dll; inetp60.dll

Then the problem is solved and gone.

By the way, I stumbled on your site searching for info on spyware and adware. For the past year I've been starting a company called Alkeli Solutions, we're developing software called Frontline which in the end will be the ultimate system cleaner, our database is now up to about 150,000 files/objects that should be removed from systems. For more information check out our site http://alkeli.cjb.net
Our site is still not complete and has yet to be moved to a different domain once it's done.

Cheers!
Al Carrier
Alkeli Solutions

Posted by: Al at September 27, 2004 10:54 PM

I don't know if this is germain to any problems you are discussing here. I had to do a complete burn-down to all 4 hd's when lop.exe got into my system. But even though that has been a great loss of files and photos (I know..backups would have been nice!), I saw something strange when I was cruising thru my pretetch files one day before all hell broke loose. All the "TYPE" in the prefetch areas were renamed "VIRUS WORM HELL". BTW: I was running XP-PRO, SP-2 and about 20 of the newest patches, Spybot S&D 1.3, AdAware (Lavasoft), SpyWareBlaster, AVG Free, the freebees (from MSN Premium) McAfee; and the new MicroSoft BIG, now renamed BETA. Using a dynamic IP generator and all the above stuff, I thought I was really safe.

What in all the world was done to the .pf files? What did the type-change have to do with anything? Was it just somebody marking their exploits?

Hijackthis found a lot of 80+ alpha-numeric addresses and junk in my IE browser, and all my anti-stuff went nuts every time something tried to change the url, which was every 10 seconds. I got gambling sites, casinos, airlines and travel tours, dating services and new car ads. At most times, my task manager posted over 300 processes running at the same time with 100% cpu use. With all the toast pop-ups from MSN Beta and Spybot and AVG going nuts, I couldn't get anything done, so I just burned it all down.

Posted by: Joe Vreeland at February 14, 2005 9:39 AM

Colombia's vice president is "baffled" by Kate Moss's success following cocaine allegations...

Posted by: Jackson Slagle at December 7, 2006 4:17 AM

Good job!

Posted by: Markus at December 11, 2006 8:35 AM

pet health insurance

Posted by: pet health insurance at December 12, 2006 6:05 AM

Good job!

Posted by: Markus at December 12, 2006 5:56 PM

Good job!

Posted by: Markus at December 12, 2006 11:20 PM

Colombia's vice president is "baffled" by Kate Moss's success following cocaine allegations...

Posted by: Easton Smalley at December 14, 2006 4:50 AM
Post a comment









Remember personal info?