EndurerOriginal
2006-09-08 th1Version
On a computer of a netizen, The hxxp: // www.dududuw.com advertisement window is always displayed when I use IE to browse the webpage.
Use hijackthis (which can be downloaded from hxxp: // endurer.ys168.com) to scan logs and find suspicious items:
/-----------
Logfile of hijackthis v1.99.1
Scan saved at 20:20:12, on
Platform: Windows XP SP2 (winnt 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
O2-BHO: shdocvwhlp class-{BE442802-3911-46E0-B227-076B15A4EAD3}-C:/Windows/system32/mssnmp16.dll
O9-extra button: Fantastic Game-{D1EDDE84-E67E-4ccd-B28E-73AD3B71A7C9}-http://bars.duole8.com/(file missing)
O9-extra 'tool' menuitem: Fantastic Game-{D1EDDE84-E67E-4ccd-B28E-73AD3B71A7C9}-http://bars.duole8.com/(file missing)
O21-ssodl: systime-{724c75f1-b757-408d-a50a-4cf99da35d73}-C:/progra ~ 1/winkld. dll
-----------/
Find the file with WinRAR:
/-----------
C:/Windows/system32/mssnmp16.dll
-----------/
After the backup is packaged, delete it.
Uninstall: Windows Calendar (winkalendar)
Close all browsers and folders, use hijackthis to scan and fix the items listed above.
Clear temporary ie folders
Clear C:/Documents ents and settings/user/Local Settings/temp (where user is the user name)
Status: finishedcomplete scanning result of "mssnmp16.dll", received in virustotal at 09.08.2006, 14:57:10 (CET ).
Antivirus |
Version |
Update |
Result |
AntiVir |
7.1.1.16 |
09.08.2006 |
TR/spy. Agent. JP |
Authentium |
4.93.8 |
09.08.2006 |
No virus found |
Avast |
4.7.844.0 |
09.08.2006 |
No virus found |
AVG |
386 |
09.08.2006 |
No virus found |
BitDefender |
7.2 |
09.08.2006 |
No virus found |
Cat-quickheal |
8.00 |
09.07.2006 |
No virus found |
ClamAV |
Devel-20060426 |
09.08.2006 |
No virus found |
Drweb |
4.33 |
09.08.2006 |
No virus found |
ETrust-inoculateit |
23.72.119 |
09.08.2006 |
No virus found |
ETrust-vet |
30.3.3068 |
09.08.2006 |
No virus found |
Ewido |
4.0 |
09.05.2006 |
No virus found |
Fortinet |
2.77.0.0 |
09.07.2006 |
No virus found |
F-Prot |
3.16f |
09.08.2006 |
No virus found |
F-Prot4 |
4.2.1.29 |
09.07.2006 |
No virus found |
Ikarus |
0.2.65.0 |
09.08.2006 |
No virus found |
Kaspersky |
4.0.2.24 |
09.08.2006 |
No virus found |
McAfee |
4847 |
09.07.2006 |
No virus found |
Microsoft |
1.1560 |
09.08.2006 |
No virus found |
Nod32v2 |
1.1745 |
09.08.2006 |
No virus found |
Norman |
5.90.23 |
09.08.2006 |
No virus found |
Panda |
9.0.0.4 |
09.07.2006 |
No virus found |
Sophos |
4.09.0 |
09.08.2006 |
No virus found |
Symantec |
8.0 |
09.08.2006 |
No virus found |
Thehacker |
5.9.8.208 |
09.08.2006 |
No virus found |
Una |
1.83 |
09.07.2006 |
No virus found |
Vba32 |
3.11.1 |
09.07.2006 |
No virus found |
Virusbuster |
4.3.7: 9 |
09.08.2006 |
No virus found |
Aditional Information |
File Size: 233472 bytes |
MD5: 7efdae2d9d17d52d855cf6560a21b906 |
Sha1: 831369c5aa26360b9ace5ec8eea51d77c97968d4 |