smitRem log file
version 2.2
by noahdfear
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Pre-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system folder ~~~
intell32.exe
oleext.dll
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~~ wininet.dll ~~~~
wininet.dll Present!!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system folder ~~~
oleext.dll
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~~ wininet.dll ~~~~
wininet.dll INFECTED!!
Mwav results
Wed Aug 03 16:15:20 2005 => ***** Scanning complete. *****
Wed Aug 03 16:15:20 2005 => Total Objects Scanned: 5789
Wed Aug 03 16:15:20 2005 => Total Virus(es) Found: 4
Wed Aug 03 16:15:20 2005 => Total Disinfected Files: 0
Wed Aug 03 16:15:20 2005 => Total Files Renamed: 0
Wed Aug 03 16:15:20 2005 => Total Deleted Objects: 0
Wed Aug 03 16:15:20 2005 => Total Errors: 84
Wed Aug 03 16:15:20 2005 => Time Elapsed: 00:15:38
Wed Aug 03 16:15:20 2005 => Virus Database Date: 2005/07/29
Wed Aug 03 16:15:20 2005 => Virus Database Count: 140525
Wed Aug 03 16:15:20 2005 => Scan Completed.
File C:\WINDOWS\SYSTEM\intell32.exe infected by "Trojan.Win32.Small.ev" Virus! Action Taken: No Action Taken.
Object "DyFuCA Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.smartsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "CWS.smartsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\jao.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\jao.dll". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D3B1DE00-6B94-1069-8754-08002B2BD64F}" refers to invalid object "C:\WINDOWS\SYSTEM\disktool.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{E05592E4-C0B5-11D0-A439-00A0C9223196}" refers to invalid object "ksqmf.ax". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CD9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDC-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDD-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDE-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CDF-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE0-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE1-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CED-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE2-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE3-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{35461E30-C488-11d1-960E-00C04FBD7C09}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE6-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE7-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE8-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CE9-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEA-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FD853CEB-7F86-11d0-8252-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5A580C11-E5EB-11d1-A86E-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{BB847B8A-054A-11d2-A894-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EA678830-235D-11d2-A8B6-0000F8084F96}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{05300401-BCBC-11d0-85E3-00C04FD85AB4}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{64577982-86D7-11d1-BDFC-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1C82EAD9-508E-11D1-8DCF-00C04FB951F9}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{B0D17FC2-7BC4-11d1-BDFA-00C04FA31009}" refers to invalid object "C:\WINDOWS\SYSTEM\INETCOMM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{3E9BAF2D-7A79-11d2-9334-0000F875AE17}" refers to invalid object "C:\WINDOWS\SYSTEM\MSCONF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{068B0700-718C-11d0-8B1A-00A0C91BC90E}" refers to invalid object "C:\WINDOWS\SYSTEM\MSCONF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{07970B30-A4DA-11D2-B724-00104BC51339}" refers to invalid object "C:\PROGRAM FILES\NETMEETING\CONFMRSL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{507708CC-A74A-11d2-9351-0000F875AE17}" refers to invalid object "C:\WINDOWS\SYSTEM\MSCONF.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{06CE0C3A-8917-11D1-AA78-00C04FC9B202}" refers to invalid object "C:\PROGRA~1\NETMEE~1\RRCM.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4590F812-1D3A-11D0-891F-00AA004B2E24}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{674B6698-EE92-11D0-AD71-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C71566F2-561E-11D1-AD87-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{49353C99-516B-11D1-AEA6-00C04FB68820}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{71285C44-1DC0-11D2-B5FB-00104B703EFD}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{1B1CAD8C-2DAB-11D2-B604-00104B703EFD}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7A0227F6-7108-11D1-AD90-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6C19BE35-7500-11D1-AD94-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\FASTPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{D2D588B5-D081-11D0-99E0-00C04FC2F8EC}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WMIPROV.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0725C3CB-FEFB-11D0-99F9-00C04FC2F8EC}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WMIPROV.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FE9AF5C0-D3B6-11CE-A5B6-00AA00680C3F}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\STDPROV.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{72967901-68EC-11D0-B729-00AA0062CBB7}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\STDPROV.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FA77A74E-E109-11D0-AD6E-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\STDPROV.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CB8555CC-9128-11D1-AD9B-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMCORE.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{CD184336-9128-11D1-AD9B-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMCORE.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4FA18276-912A-11D1-AD9B-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMCORE.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{76A64158-CB41-11D1-8B02-00600806D9B6}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{75718C9A-F029-11D1-A1AC-00C04FB6C223}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9AED384E-CE8B-11D1-8B05-00600806D9B6}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{172BDDF8-CEEA-11D1-8B05-00600806D9B6}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5791BC26-CE9C-11D1-97BF-0000F81E849C}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C2FEEEAC-CFCD-11D1-8B05-00600806D9B6}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMDISP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5D08B586-343A-11D0-AD46-00C04FD8FDFF}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMESS.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{F7CE2E13-8C90-11D1-9E7B-00C04FC324A8}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{A1044801-8F7E-11D1-9E7C-00C04FC324A8}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMPROX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7C857801-7381-11CF-884D-00AA004B2E24}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMSVC.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{DDBABFC0-2648-11D2-BC64-00104B2CF71C}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\CIMW32EX.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{9A653086-174F-11D2-B5F9-00104B703EFD}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMCOMN.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{EB87E1BD-3233-11D2-AEC9-00C04FB68820}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\WBEMCOMN.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{6DAF9757-2E37-11D2-AEC9-00C04FB68820}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\MOFD.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{C10B4771-4DA0-11D2-A2F5-00C04F86FB7D}" refers to invalid object "C:\WINDOWS\SYSTEM\WBEM\MOFD.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{53DEFDE0-9222-11CF-9ED3-00AA004C120C}" refers to invalid object "C:\WINDOWS\SYSTEM\WEBPOST.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{33675000-9B48-11D0-AD53-00AA00A219AA}" refers to invalid object "C:\WINDOWS\SYSTEM\WEBPOST.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{96E31637-59F3-11D0-AD1F-00AA00A219AA}" refers to invalid object "C:\WINDOWS\SYSTEM\WPWIZDLL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{8B14B770-748C-11D0-A309-00C04FD7CFC5}" refers to invalid object "C:\WINDOWS\SYSTEM\POSTWPP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{FFCF1E40-7978-11D0-B1C9-00AA006DCDF4}" refers to invalid object "C:\WINDOWS\SYSTEM\CRSWPP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{02B5E1D1-8B7C-11D0-AD45-00AA00A219AA}" refers to invalid object "C:\WINDOWS\SYSTEM\FTPWPP.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{886e7bf0-c867-11cf-b1ae-00aa00a3f2c3}" refers to invalid object "C:\PROGRAM FILES\WEB PUBLISH\FLUPL.OCX". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}" refers to invalid object "C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMGETALL.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{0055C089-8582-441B-A0BF-17B458C2A3A8}" refers to invalid object "C:\PROGRAM FILES\INTERNET DOWNLOAD MANAGER\IDMIECC.DLL". Action Taken: No Action Taken.
Entry "HKCR\Overview.Document" refers to invalid object "{DA23B9C9-6893-11D0-8534-00C04FD7AD0C}". Action Taken: No Action Taken.
Entry "HKCR\cnkf9.e4vh02" refers to invalid object "{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}". Action Taken: No Action Taken.
Entry "HKCR\cnkf9.e4vh02.857" refers to invalid object "{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}". Action Taken: No Action Taken.
Entry "HKCR\1f80k2.8g3b" refers to invalid object "{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}". Action Taken: No Action Taken.
Entry "HKCR\1f80k2.8g3b.55" refers to invalid object "{467FAEB2-5F5B-4c81-BAE0-2A4752CA7F4E}". Action Taken: No Action Taken.
During the mwav scan, I saw this in the what was scanned.
Wed Aug 03 16:13:08 2005 => Result: ERROR!!! File C:\WINDOWS\TEMP\PSGuardInstall.exe is Not Scanned
Just thought I'd point that out, not sure if it means much.