OK, been following the instructions. I couldn't find any of the tasks running that you mentioned in point 3
In point 5 I could not find
C:\WINDOWS\System32\jdcj.dll
and you said to look for other .exe .dll and .dat files. There seemed to be loads of these in C:\WINDOWS\System32 and so didn't know which to delete.
Here are the results from those you wanted me to run...
Logfile of HijackThis v1.99.1
Scan saved at 17:17:49, on 20/03/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\devldr32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\HijackThis.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
-- Scan 1 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
-- Scan 2 ---------------------------
About:Buster Version 4.0
Reference List : 25
ADS not scanned System(FAT)
Attempted Clean Of Temp folder.
Pages Reset... Done!
-------------------------------------------------------------------
A bit worried about all those found in Pandasoftware, especially the se.dll!
Incident Status Location
Adware:Adware/CWS.HomeSearchAsisstantNo disinfected Windows Registry
Virus:Trj/Small.GV Disinfected C:\Recycled\Q330995.exe
Spyware:Spyware/LocalNRD No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\THI32E9.tmp\localNrd.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\conscorr.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\conscorr.ini
Adware:Adware/Comet No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\unpack\CC_43.inf
Adware:Adware/Comet No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\unpack\inst43.exe
Adware:Adware/WinTools No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\~543680.tmp
Adware:Adware/WinTools No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\~480133.tmp
Adware:Adware/SearchExe No disinfected C:\Documents and Settings\Hayley\Local Settings\Temp\se.dll
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-009[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-011[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-013[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-003[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-004[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-005[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-009[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-058[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-011[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-069[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-071[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-013[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-074[2].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-079[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-pictures-014[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-093[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\george-eads-picture-104[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\eric-bana-pictures[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\sean-bean-pictures[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\sean-bean-pictures-003[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\celebrities%20pictures[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\G16VWT2F\webhostingtroops[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-006[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-002[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-007[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-041[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-010[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-061[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-012[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-083[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-084[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-085[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-016[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-picture-100[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\george-eads-pictures-018[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\search[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\sean-bean-pictures-002[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\GXIRS5AR\sean-bean-pictures-004[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-010[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-012[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-014[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-047[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-056[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-060[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-062[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-068[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-070[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-072[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-picture-078[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-pictures-015[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\george-eads-pictures-017[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\search[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\MTGRAPQ5\julian-mcmahon-pictures-002[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-016[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-pictures-006[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-pictures-008[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-051[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-055[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-073[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-088[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\george-eads-picture-097[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\julian-mcmahon-pictures[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\search[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\sean-bean-picture-005[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\sean-bean-picture-018[1].htm
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\C9GVKZWN\celebrities%20pictures[1].htm
Adware:Adware/MediaTickets No disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\EQ2XPLSE\CAP8WZTT.htm
Virus:Trj/Small.GV Disinfected C:\Documents and Settings\Hayley\Local Settings\Temporary Internet Files\Content.IE5\EQ2XPLSE\AFkhDJrHUhv4TDo9oWBH[1].chm
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Guest\Local Settings\Temp\conscorr.inf
Adware:Adware/IPInsight No disinfected C:\Documents and Settings\Guest\Local Settings\Temp\conscorr.ini
Adware:Adware/CWS.Aboutblank No disinfected C:\Program Files\backups\backup-20050313-184009-912.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\Program Files\backups\backup-20050313-185006-868.dll
Adware:Adware/CWS.Aboutblank No disinfected C:\Program Files\backups\backup-20050320-135856-555.dll
Virus:Trj/Small.AG Disinfected G:\RECYCLED\1.exe
Virus:Trojan Horse Disinfected G:\WINDOWS\SYSTEM\corelsys.dll
Virus:Trj/Downloader.AJW Disinfected G:\WINDOWS\SYSTEM\services\WMPLAYER.EXE
Virus:Trj/Downloader.DJ Disinfected G:\WINDOWS\SYSTEM\services\SERVICES.EXE
Virus:Trj/Downloader.AES Disinfected G:\WINDOWS\SYSTEM\c_10230.dll
Virus:Trj/Small.AG Disinfected G:\WINDOWS\SYSTEM\xdldr24.exe
Adware:Adware/PurityScan No disinfected G:\WINDOWS\SYSTEM\wapisvtr.exe
Adware:Adware/Aureate-Radiate No disinfected G:\WINDOWS\SYSTEM\adimage.dll
Adware:Adware/Aureate-Radiate No disinfected G:\WINDOWS\SYSTEM\tfde.dll
Adware:Adware/Aureate-Radiate No disinfected G:\WINDOWS\SYSTEM\msipcsv.exe
Adware:Adware/Aureate-Radiate No disinfected G:\WINDOWS\SYSTEM\ipcclient.dll
Adware:Adware/Aureate-Radiate No disinfected G:\WINDOWS\SYSTEM\htmdeng.exe
Adware:Adware/MediaTickets No disinfected G:\WINDOWS\TEMP\ICD1.tmp\MediaTicketsInstaller.INF
Adware:Adware/MediaTickets No disinfected G:\WINDOWS\TEMP\ICD1.tmp\MediaTicketsInstaller.ocx
Spyware:Spyware/Bridge No disinfected G:\WINDOWS\Downloaded Program Files\jao.dll
Adware:Adware/MediaTickets No disinfected G:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx
Adware:Adware/MediaTickets No disinfected G:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.INF
Virus:Trj/Downloader.AJW Disinfected G:\Program Files\Windows Media Player\WMPLAYER.EXE
Virus:Trj/Downloader.DJ Disinfected G:\Program Files\Tesconet\services.exe
Virus:Trojan Horse No disinfected G:\_Restore\ARCHIVE\FS175.CAB[A0089309.CPY]
Virus:Trj/Small.AG No disinfected G:\_Restore\ARCHIVE\FS176.CAB[A0089352.CPY]
Virus:Trj/Small.AG No disinfected G:\_Restore\ARCHIVE\FS176.CAB[A0089407.CPY]
Virus:Trj/Small.AG No disinfected G:\_Restore\ARCHIVE\FS181.CAB[A0089656.CPY]
Virus:Trj/Small.AG No disinfected G:\_Restore\ARCHIVE\FS185.CAB[A0089930.CPY]
Virus:Trj/Small.AG No disinfected G:\_Restore\ARCHIVE\FS185.CAB[A0089931.CPY]
----------------------------------------------------------------------------------------------
Housecall found the same files as panda, namely...TROJ_STARTPAG.GJ Non cleanable C:\Documents and Settings\Hayley\Local Settings\Temp\se.dll
TROJ_STARTPAG.GP Non cleanable C:\Program Files\backups\backup-20050313-184009-912.dll
TROJ_STARTPAG.GP Non cleanable C:\Program Files\backups\backup-20050313-185006-868.dll
TROJ_STARTPAG.GP Non cleanable C:\Program Files\backups\backup-20050320-135856-555.dll
TROJ_SMALL.GF Non cleanable G:\_Restore\ARCHIVE\FS175.CAB[A0089309.CPY]
TROJ_SMALL.GN Non cleanable G:\_Restore\ARCHIVE\FS176.CAB[A0089352.CPY]
TROJ_SMALL.GN Non cleanable G:\_Restore\ARCHIVE\FS176.CAB[A0089407.CPY]
TROJ_SMALL.GN Non cleanable G:\_Restore\ARCHIVE\FS181.CAB[A0089656.CPY]
TROJ_SMALL.GN Non cleanable G:\_Restore\ARCHIVE\FS185.CAB[A0089930.CPY]
TROJ_SMALL.GN Non cleanable G:\_Restore\ARCHIVE\FS185.CAB[A0089931.CPY]
----------------------------------------------------------------------------------
I've opened IE and it doesn't seem to go to the old about:blank.
Thanks.
Stephen