Re: VIRUS or sumthing!!

From: Mike Burgess (winhelp2002_at_spamthis.com)
Date: 12/25/03


Date: Thu, 25 Dec 2003 08:28:33 -0500

Bob,
"ftapp" = Parasite.FlashTrack
http://www.doxdesk.com/parasite/FlashTrack.html

Dealing with Unwanted Spyware, Parasites, Toolbars and Search Engines
http://mvps.org/winhelp2002/unwanted.htm
____________________________________________________________
Mike Burgess [MVP Windows Shell\User] http://www.mvps.org/winhelp2002/
Blocking Spyware, Adware, Parasites, Hijackers, Trojans, with a HOSTS file
http://www.mvps.org/winhelp2002/hosts.htm [updated 12-19-03]
Please post replies to this Newsgroup, email address is invalid

--
"BOB" <anonymous@discussions.microsoft.com> wrote in message
news:07cd01c3ca00$4d66a850$a101280a@phx.gbl...
> hey, ive got either a virus norton cant pick up, or
> sumthin like that, because it wont allow access to
> internet explorer in one of my xp accounts. explorer
> opens, and then shut downs almost instaniously!i have
> traced the problem back to a file on my C: drive,
> called "ftapp.txt", i can open it, and it reads:
> "STDOUT HAS JUSTBEEN OPENED...
> Invoke: NAVIGATECOMPLETE2 EVENT RECEIVED
>         URL: http://loginnet.passport.com/login.srf?
> id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=12
> 96000&lc=3081&_lang=EN&RU=http%3a%2f%
> 2fwww.hotmail.msn.com%2fcgi-bin%2fsbox%3frru%3d%252fcgi-
> bin%252fhmhome%26reason%3dnocookies
>         CURRENT TIME: 1072251872
>         LAST AD TIME: 0
>         AD WAIT TIME: 400
> Invoke: Checking URL
> http://loginnet.passport.com/login.srf?
> id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=12
> 96000&lc=3081&_lang=EN&RU=http%3a%2f%
> 2fwww.hotmail.msn.com%2fcgi-bin%2fsbox%3frru%3d%252fcgi-
> bin%252fhmhome%26reason%3dnocookies
> GetAlternateSite: Called
> for 'loginnet.passport.com/login.srf?
> id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=12
> 96000&lc=3081&_lang=EN&RU=http%3a%2f%
> 2fwww.hotmail.msn.com%2fcgi-bin%2fsbox%3frru%3d%252fcgi-
> bin%252fhmhome%26reason%3dnocookies'
> GetAlternateSite: 'humana.com/'
> <=> 'loginnet.passport.com/login.srf?
> id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&fsat=12
> 96000&lc=3081&_lang=EN&RU=http%3a%2f%
> 2fwww.hotmail.msn.com%2fcgi-bin%2fsbox%3frru%3d%252fcgi-
> bin%252fhmhome%26reason%3dnocookies'  -> -1
> GetAlternateSite: 'ppsa.com/'
> <=> 'loginnet.passport.com/login.srf?
> id=2&svc=mail&cbid=24325&msppjph=1&tw=0&fs=1&fsa=1&Invoke:
>  NAVIGATECOMPLETE2 EVENT RECEIVED
>         URL: ::{20D04FE0-3AEA-1069-A2D8-08002B30309D}
>         CURRENT TIME: 1072252236
>         LAST AD TIME: 0
>         AD WAIT TIME: 400
> Doc_TitleText_Search: Starting
> Doc_TitleText_Search: Got Document
> Doc_MetaText_Search: Starting
> Doc_MetaText_Search: Got Document
> Invoke: NAVIGATECOMPLETE2 EVENT RECEIVED
>         URL: C:\Documents and Settings\All Users\Documents
>         CURRENT TIME: 1072252240
>         LAST AD TIME: 0
>         AD WAIT TIME: 400
> Doc_TitleText_Search: Starting
> Doc_TitleText_Search: Got Document
> Doc_MetaText_Search: Starting
> Doc_MetaText_Search: Got Document
> Invoke: NAVIGATECOMPLETE2 EVENT RECEIVED
>         URL: C:\Documents and Settings\All
> Users\Documents\My Music
>         CURRENT TIME: 1072252242
>         LAST AD TIME: 0
>         AD WAIT TIME: 400
> Doc_TitleText_Search: Starting
> Doc_TitleText_Search: Got Document
> Doc_MetaText_Search: Starting
> Doc_MetaText_Search: Got Document"
>
> I've got no idea what this means, but wen i start the
> computer and go straight to the .txt file, it is empty,
> once i open a program like explorer, it fills with all
> this code and stuff! i've tried deleting the file, but it
> says it is being used by another person or program and
> can not be deleted, ive tried goin thru task manager and
> end tasking all unnecassary programs, but to no avail. if
> any one can help me with how to get rid of this
> file/virus/whateva, it would b greatly appreciated!
> Cheers,
> Bob