I couldnt find this file: C:\WINDOWS\systb.dll
I did the two virus scans, house call found nothing
this is the panda one:
Incident Status Location
Adware:Adware/eZula No disinfected C:\WINDOWS\system32\stub.exe
Spyware:Spyware/New.net No disinfected C:\Program Files\FirstLook
Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/BrilliantDigitalNo disinfected C:\WINDOWS\BDE
Spyware:Spyware/Aveo-Attune No disinfected C:\Program Files\Aveo
Adware:Adware/Hotbar No disinfected C:\WINDOWS\Downloaded Program Files\Hotbar.???
Adware:Adware/WinTools No disinfected C:\Program Files\WebSearch
Adware:Adware/TopRebates No disinfected C:\DOCUME~1\Default\LOCALS~1\Temp\jkill.exe
Adware:Adware/WildTangent No disinfected C:\Program Files\WILDTANGENT
Virus:Trj/Imiserv.D Disinfected C:\WINDOWS\snbho.exe
Spyware:Spyware/New.net No disinfected C:\WINDOWS\NDNuninstall5_48.exe
Spyware:Spyware/New.net No disinfected C:\Program Files\NewDotNet\newdotnet5_48.dll
Adware:Adware/Apropos No disinfected C:\Documents and Settings\All Users\Application Data\Viewpoint\Viewpoint Manager\Downloads\AlertSWF\contents\Exec.exe
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bg.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\c.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\ce.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\q.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\bo.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\i.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\r.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bt.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\b.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\d.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\f.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\l.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\s.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\a.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\m.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\n.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\j.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\p.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\w.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\x.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\y.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bu.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ba.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bb.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bz.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bd.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\be.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\bf.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\bh.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cb.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\bk.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cf.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bm.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bn.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\bp.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bq.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\br.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bc.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bs.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ch.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bv.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bw.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\bx.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\t.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\by.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ca.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cc.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cd.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cl.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cn.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cu.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ck.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cv.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cx.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cs.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\cp.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\cq.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\cr.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\ct.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\da.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\cz.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\db.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dc.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dd.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\de.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\u.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dv.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\df.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\di.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\h.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dw.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dl.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dx.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dm.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\dn.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\dp.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\dy.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dr.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ds.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\dt.class
Adware:Adware/MoeMoney No disinfected C:\Recycled\Dc4\System\Code\dz.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\du.class
Adware:Adware/TopMoxie No disinfected C:\Recycled\Dc4\System\Code\ed.class
Possible Virus. No disinfected C:\Recycled\Dc4\LimeShop.exe
here is the new hijack version (after clicking fix check for the ones you told me)
Logfile of HijackThis v1.99.1
Scan saved at 9:17:09 PM, on 3/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\CFGSAFE\AUTOCHK.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\ScanSoft\PaperPort\FBDirect.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\ACSD.EXE
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\WINDOWS\system32\khooker.exe
C:\WINDOWS\system32\RUNDLL32.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe
C:\Program Files\America Online 9.0c\aoltray.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\MMDiag.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AIM95\aim.exe
C:\Program Files\America Online 9.0c\waol.exe
C:\Program Files\America Online 9.0c\shellmon.exe
C:\Program Files\America Online 9.0c\aolwbspd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\rnathchk.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\unzipped\hijackthis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "
http://home.netscape.../7_1/home.html"); (C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\default\7fj9bnai.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRAM%20FILES%5CNETSCAPE%5CNETSCAPE%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Default\Application Data\Mozilla\Profiles\default\7fj9bnai.slt\prefs.js)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: BrowserHelper Class - {EBCDDA60-2A68-11D3-8A43-0060083CFB9C} - c:\WINDOWS\system32\NZDD.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ConfigSafe] C:\CFGSAFE\AUTOCHK.EXE
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PP5300usb] C:\Program Files\ScanSoft\PaperPort\FBDirect.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [LimeShop] wjview /cp:p "C:\Program Files\LimeShop\System\Code" Main lp: "C:\Program Files\LimeShop"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [RebateNation0] "C:\Program Files\Rebate_Nation\RebateNation0.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\QUICKENW\bagent.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0c\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - c:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Squelchies by pogo -
http://game3.pogo.co...s-ob-assets.cabO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/viewers/ipixx.cabO16 - DPF: {65E7DB1D-0101-4100-BD66-C5C78C917F93} (WTDMMPVersion Class) -
http://install.wildt...lim/install.cabO16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield Setup Player) -
http://www.installen...gine/isetup.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{1E08C684-AEB8-4436-8D69-37A9F05E13D6}: NameServer = 205.188.146.145
O17 - HKLM\System\CS1\Services\Tcpip\..\{1E08C684-AEB8-4436-8D69-37A9F05E13D6}: NameServer = 205.188.146.145
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\ACSD.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe