Hello,
I have problems removing malware from my notebook. I'm running Dell Latitude D800 with Windows XP Pro SP2, for security I use Norton AntiVirus 2005 with it's Internet Worm Protection enabled. My Windows and Norton AntiVirus have all the latest updates, virus definitions etc. My PC started sending tons of spam emails to unknown mailboxes yesterday, it always fills my whole screen with those Norton "sending email" dialog messages. The virus/malware also disabled Norton Auto-Protect function, so I had to reinstall Norton few times to make a virus scan.
After that, Norton found few viruses, I removed them all. After I connected my Dell back to the Internet, the problem was immediatly there again - even without touching Outlook or Explorer. I downloaded lots of trial and freeware utilities to correct the problem (fe. I still have these installed: Zone Labs Security, SpySweeper, Spybot, Ewido Anti-Malware, Spyware Doctor and +- 5 other that I already unistalled) - they all found some problems, I always fixed all of them. At the moment, none of these programs are able to find any unwanted software/virus, but my problem with sending spam emails still exists.
I followed the points in "Before you post a log" thread, so here we go!
*** On-line AntiVirus scan ***
I used eTrust Antivirus Web Scanner, the log is here:
java.jar-bae16f0-20fb491e.zip>NewSecurityClassLoader.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-bae16f0-20fb491e.zip>NewURLClassLoader.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
loaderadv661.jar-897c2ff-26503401.zip>Dummy.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
ibm00001.dll Win32/Anserin!generic cannot cure C:\Program Files\Common Files\Microsoft Shared\Web Folders\
ibm00002.dll Win32/Anserin!generic cannot cure C:\Program Files\Common Files\Microsoft Shared\Web Folders\
*** Running SpyBot in safe mode ***
SpyBot always finds some Tracing Cookies which seem to be unfixable - I always select them to be fixed, everything seems to be OK, but after some time (without even surfing on the web) they are there again. Since the log exceedes the maximum size as an text or attachment, it has to be downloaded here.
*** HiJackThis log ***
Also downloadable.
Thanks for any help in advance, it will be appreciated!
Best Reagrds,
Martin Polach
I have problems removing malware from my notebook. I'm running Dell Latitude D800 with Windows XP Pro SP2, for security I use Norton AntiVirus 2005 with it's Internet Worm Protection enabled. My Windows and Norton AntiVirus have all the latest updates, virus definitions etc. My PC started sending tons of spam emails to unknown mailboxes yesterday, it always fills my whole screen with those Norton "sending email" dialog messages. The virus/malware also disabled Norton Auto-Protect function, so I had to reinstall Norton few times to make a virus scan.
After that, Norton found few viruses, I removed them all. After I connected my Dell back to the Internet, the problem was immediatly there again - even without touching Outlook or Explorer. I downloaded lots of trial and freeware utilities to correct the problem (fe. I still have these installed: Zone Labs Security, SpySweeper, Spybot, Ewido Anti-Malware, Spyware Doctor and +- 5 other that I already unistalled) - they all found some problems, I always fixed all of them. At the moment, none of these programs are able to find any unwanted software/virus, but my problem with sending spam emails still exists.
I followed the points in "Before you post a log" thread, so here we go!
*** On-line AntiVirus scan ***
I used eTrust Antivirus Web Scanner, the log is here:
java.jar-bae16f0-20fb491e.zip>NewSecurityClassLoader.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
java.jar-bae16f0-20fb491e.zip>NewURLClassLoader.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
loaderadv661.jar-897c2ff-26503401.zip>Dummy.class Java/ByteVerify!exploit cannot cure C:\Documents and Settings\metchoun\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\
ibm00001.dll Win32/Anserin!generic cannot cure C:\Program Files\Common Files\Microsoft Shared\Web Folders\
ibm00002.dll Win32/Anserin!generic cannot cure C:\Program Files\Common Files\Microsoft Shared\Web Folders\
*** Running SpyBot in safe mode ***
SpyBot always finds some Tracing Cookies which seem to be unfixable - I always select them to be fixed, everything seems to be OK, but after some time (without even surfing on the web) they are there again. Since the log exceedes the maximum size as an text or attachment, it has to be downloaded here.
*** HiJackThis log ***
Also downloadable.
Thanks for any help in advance, it will be appreciated!
Best Reagrds,
Martin Polach