Author Topic: Bloodhound.w32.ep or win32/Nsag  (Read 1838 times)

Offline Jagger8dogs

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
Bloodhound.w32.ep or win32/Nsag
« Reply #20 on: April 02, 2006, 09:24:32 PM »
Okay when I right clicked and clicked on open with, the usual list of programs from which you can select doesn't open.  Sorry for lack of detail.  Will detail better from now on. http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/unsure.gif\' class=\'bbc_emoticon\' alt=\':unsure:\' />

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Bloodhound.w32.ep or win32/Nsag
« Reply #21 on: April 02, 2006, 09:28:25 PM »
Set Windows To Show Hidden Files and Folders
    * Click Start.
    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Can you look for this file and let me know if you find it please

C:\WINDOWS\SYSTEM32\oleext.dll <-this file

Go to either of these links
http://virusscan.jotti.org/
or
http://www.virustotal.com/flash/index_en.html

Use the browse button and navigate to this file on your hard disk
C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll<--this file

Right click on the file and choose Select
Then use the Submit button
Let it finish scanning
Could you post back the results of the scan back here please

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Jagger8dogs

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
Bloodhound.w32.ep or win32/Nsag
« Reply #22 on: April 02, 2006, 09:45:14 PM »
oleext.dll was not in the folder

Below is from the online virus scan you requested.  I did both sites but could not pull the info from the first neither site found any virus in the file.


This is a report processed by VirusTotal on 04/03/2006 at 04:41:50 (CET) after scanning the file "wininet.dll" file.
Antivirus Version Update Result
AntiVir 6.34.0.14 04.02.2006 no virus found
Avast 4.6.695.0 04.01.2006 no virus found
AVG 386 03.31.2006 no virus found
Avira 6.34.0.54 04.02.2006 no virus found
BitDefender 7.2 04.02.2006 no virus found
CAT-QuickHeal 8.00 03.31.2006 no virus found
ClamAV devel-20060202 04.03.2006 no virus found
DrWeb 4.33 04.02.2006 no virus found
eTrust-InoculateIT 23.71.118 04.02.2006 no virus found
eTrust-Vet 12.4.2145 03.31.2006 no virus found
Ewido 3.5 04.02.2006 no virus found
Fortinet 2.71.0.0 04.03.2006 no virus found
F-Prot 3.16c 03.30.2006 no virus found
Ikarus 0.2.59.0 04.01.2006 no virus found
Kaspersky 4.0.2.24 04.03.2006 no virus found
McAfee 4731 03.31.2006 no virus found
NOD32v2 1.1467 04.02.2006 no virus found
Norman 5.70.10 03.31.2006 no virus found
Panda 9.0.0.4 04.02.2006 no virus found
Sophos 4.04.0 04.02.2006 no virus found
Symantec 8.0 04.03.2006 no virus found
TheHacker 5.9.7.124 04.03.2006 no virus found
UNA 1.83 03.30.2006 no virus found
VBA32 3.10.5 04.03.2006 no virus found

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Bloodhound.w32.ep or win32/Nsag
« Reply #23 on: April 02, 2006, 09:49:11 PM »
Can you do the following please

Reboot into safe mode
Navigate too this folder
C:\WINDOWS\SYSTEM32

Find "wininet.dll"
Right click on it and rename it too wininet.old
Then go to this folder
C:\WINDOWS\SYSTEM32\DLLCACHE
Right click on "wininet.dll" and copy it from the menu bar
Then Paste it into the System32 folder

Reboot back to Normal mode

Does that help at all in running any programs?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Jagger8dogs

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
Bloodhound.w32.ep or win32/Nsag
« Reply #24 on: April 02, 2006, 10:00:31 PM »
I don't have the folder C:\WINDOWS\SYSTEM32\DLLCACHE.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Bloodhound.w32.ep or win32/Nsag
« Reply #25 on: April 02, 2006, 10:12:50 PM »
The DLLCache folder is a hidden folder
I asked you earlier to
Set Windows To Show Hidden Files and Folders

    * Open My Computer.
    * Select the Tools menu and click Folder Options.
    * Select the View Tab.
    * Under the Hidden files and folders heading select Show hidden files and folders.
    * Uncheck the Hide protected operating system files (recommended) option.
    * Uncheck the Hide Extensions for known file types
    * Click Yes to confirm.
    * Click OK.

Which "wininet.dll" did you scan at VirusTotal
I asked you too scan the one in this folder
C:\WINDOWS\SYSTEM32\DLLCACHE <-this folder
If that's not the one you scanned, do it NOW please
I want to make sure it's not infected
« Last Edit: April 02, 2006, 10:15:52 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Jagger8dogs

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
Bloodhound.w32.ep or win32/Nsag
« Reply #26 on: April 02, 2006, 10:17:49 PM »
I will scan it now.  I looked for the folder, including showing hidden folders but could not find.  Doing again now.

Offline Jagger8dogs

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
Bloodhound.w32.ep or win32/Nsag
« Reply #27 on: April 02, 2006, 10:33:12 PM »
Okay I did scan the correct file before as you directed.  I just wasn't aware of it until going back and reading the posts.  Even after switching to show hidden files and folders I still could not see the folder.  But when I did the online scan, I just cut and pasted the address you provided.  I was able to still find the hidden folder via explorer.  I Changed the name of wininet.dll in the System32 folder to wininet.old.  I then copied and pasted the wininet.dll from the Dllcache folder into the system32 folder and restarted into normal mode.  I noticed no difference.  What is the easiest way to run a repair on my operating system?  I am TAD right now and all of my software is in Japan.  Thanks again.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
Bloodhound.w32.ep or win32/Nsag
« Reply #28 on: April 02, 2006, 11:21:30 PM »
To do a repair on the system you need your XP CD
But before you go that route
If you never got the chance to uninstall one of your AV's can open
MyComputer>>C:\Documents and Settings\All Users\Start Menu\Programs\\AVG Free Edition
and run the uninstaller for AVG

Reboot if prompted

Back in Windows
Use Internet Explorer
Go to Panda's using the following link
http://www.pandasoftware.com/products/activescan.htm
*Once you are on the Panda site click the Scan your PC button.
*A new window will open...click the Check Now button.
    *Enter your
Country
*Enter your State/Province
*Enter your e-mail address and click send
*Select either Home User or Company
*Click the big Scan Now button
[/list]If it wants to install an ActiveX component allow it
*It will start downloading the files it requires for the scan [color=\"blue\"](Note: It may take a couple of minutes)[/color]
*When the download is complete, click on My Computer to start the scan
*When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.

Reboot the computer

Can you post the report back here please
try and open the report in Wordpad if notepad won't work
MyComputer>>C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\Wordpad
Use the FILE>>OPEN from the menu bar
In the file types choose All Documents from the drop down bar so you can view all files
« Last Edit: April 03, 2006, 12:08:53 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here