Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Spy Sheriff [RESOLVED]


  • This topic is locked This topic is locked

#46
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I will run the Scan and hope!

I am using outlook

Terry
  • 0

Advertisements


#47
Guest_usetobe_*

Guest_usetobe_*
  • Guest
HHmm repair install doesn't overwrite office componants...you got your office disc?.

Post results of virus scan, if it finds anything it won't be in your windows , if ny thing it may find any infected files you have downloaded etc.
  • 0

#48
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I can probably reload lost components given time and patience!!

Kaspersky ran ok this time and i attach the log. I have had to copy it to another machine in order to email it so I hope it is all there.

There were a number of files which it could not scan because they were password protected. I made a note of them just in case they do not show up on the report.

Terry

"Task start time: 30/06/2005 17:22:03"
"Task completion time: 30/06/2005 17:52:19"
"Objects scanned: 81600"
"Viruses detected: 31"
"Viruses disinfected: 0"
"Objects deleted: 31"
"Objects quarantined: 0"

Settings:
Objects to be scanned:
My Computer
If an infected object is found:
Prompt user for action
Scan level:
Recommended
Objects to be excluded from the scan scope:
Option not used

Report:
C:\127062.exe;is infected with a virus Trojan-Proxy.Win32.Sobit.e;30/06/2005 17:24:34
C:\127062.exe;deleted;30/06/2005 17:24:51
C:\protect.exe;is infected with a virus Trojan-Downloader.Win32.Agent.nr;30/06/2005 17:24:51
C:\protect.exe;deleted;30/06/2005 17:24:51
C:\q257446.exe;is infected with a virus Trojan-Downloader.Win32.Small.amb;30/06/2005 17:24:54
C:\q257446.exe;deleted;30/06/2005 17:24:54
C:\!Submit\wp.bmp;is infected with a virus not-virus:BadJoke.Win32.Nsag.a;30/06/2005 17:24:54
C:\!Submit\wp.bmp;deleted;30/06/2005 17:24:54
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:25:50
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap1.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:25:53
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap1.zip;password protected has not been processed;30/06/2005 17:26:06
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap2.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:26:14
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap2.zip;password protected has not been processed;30/06/2005 17:26:17
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap3.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:26:49
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchBadZoneMap3.zip;password protected has not been processed;30/06/2005 17:26:49
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGooglems.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:27:07
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchGooglems.zip;password protected has not been processed;30/06/2005 17:27:07
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp.zip\svchost.exe;password protected has not been processed;30/06/2005 17:27:26
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp2.zip\svchost.exe;password protected has not been processed;30/06/2005 17:27:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp2.zip;password protected has not been processed;30/06/2005 17:27:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp3.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:27:37
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\CoolWWWSearchOleHelp3.zip;password protected has not been processed;30/06/2005 17:27:47
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\DyFuCA.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:27:50
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar.zip\red_kas221.ico;password protected has not been processed;30/06/2005 17:28:17
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar1.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:28:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar10.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar11.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:34
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar12.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar13.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:37
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar14.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:38
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar15.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:39
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar16.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:40
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar17.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:41
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar18.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:42
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar19.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:42
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar2.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:28:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar2.zip;password protected has not been processed;30/06/2005 17:28:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar20.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar21.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar21.zip;password protected has not been processed;30/06/2005 17:28:47
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar22.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:48
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar22.zip;password protected has not been processed;30/06/2005 17:28:49
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar23.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:28:50
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar23.zip;password protected has not been processed;30/06/2005 17:28:52
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar24.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:29:02
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar24.zip;password protected has not been processed;30/06/2005 17:29:03
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar25.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:04
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar25.zip;password protected has not been processed;30/06/2005 17:29:06
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar26.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:07
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar26.zip;password protected has not been processed;30/06/2005 17:29:07
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar27.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:14
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar27.zip;password protected has not been processed;30/06/2005 17:29:15
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar28.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:19
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar28.zip;password protected has not been processed;30/06/2005 17:29:20
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar29.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:22
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar29.zip;password protected has not been processed;30/06/2005 17:29:23
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar3.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:29:25
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar3.zip;password protected has not been processed;30/06/2005 17:29:26
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar30.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:27
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar30.zip;password protected has not been processed;30/06/2005 17:29:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar31.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar31.zip;password protected has not been processed;30/06/2005 17:29:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar32.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar32.zip;password protected has not been processed;30/06/2005 17:29:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar33.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar33.zip;password protected has not been processed;30/06/2005 17:29:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar34.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:34
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar34.zip;password protected has not been processed;30/06/2005 17:29:35
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar35.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar35.zip;password protected has not been processed;30/06/2005 17:29:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar36.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:38
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar36.zip;password protected has not been processed;30/06/2005 17:29:38
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar37.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:40
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar37.zip;password protected has not been processed;30/06/2005 17:29:41
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar38.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:41
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar38.zip;password protected has not been processed;30/06/2005 17:29:42
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar39.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar39.zip;password protected has not been processed;30/06/2005 17:29:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar4.zip\red_kas221.ico;password protected has not been processed;30/06/2005 17:29:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar4.zip;password protected has not been processed;30/06/2005 17:29:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar40.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:45
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar40.zip;password protected has not been processed;30/06/2005 17:29:46
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar41.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:47
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar41.zip;password protected has not been processed;30/06/2005 17:29:47
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar43.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:29:49
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar5.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:29:50
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar5.zip;password protected has not been processed;30/06/2005 17:29:51
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar6.zip\red_kas21.ico;password protected has not been processed;30/06/2005 17:29:54
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar6.zip;password protected has not been processed;30/06/2005 17:29:54
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar7.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:55
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar8.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:56
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar9.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:57
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:29:58
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechPowerScan1.zip\sbRecovery.ini;password protected has not been processed;30/06/2005 17:29:58
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor1.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:00
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor1.zip;password protected has not been processed;30/06/2005 17:30:01
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor2.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:27
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor2.zip;password protected has not been processed;30/06/2005 17:30:28
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor3.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:28
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor3.zip;password protected has not been processed;30/06/2005 17:30:29
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor4.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:29
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor4.zip;password protected has not been processed;30/06/2005 17:30:29
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor5.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor5.zip;password protected has not been processed;30/06/2005 17:30:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor6.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor6.zip;password protected has not been processed;30/06/2005 17:30:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MediaMotor7.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:30
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings.zip\objsafe.tlb;password protected has not been processed;30/06/2005 17:30:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings10.zip\objsafe.tlb;password protected has not been processed;30/06/2005 17:30:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings2.zip\objsafe.tlb;password protected has not been processed;30/06/2005 17:30:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings2.zip;password protected has not been processed;30/06/2005 17:30:31
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings3.zip\objsafe.tlb;password protected has not been processed;30/06/2005 17:30:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings3.zip;password protected has not been processed;30/06/2005 17:30:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings4.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings4.zip;password protected has not been processed;30/06/2005 17:30:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings5.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:32
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings5.zip;password protected has not been processed;30/06/2005 17:30:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings6.zip\sbRecovery.ini;password protected has not been processed;30/06/2005 17:30:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings7.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings7.zip;password protected has not been processed;30/06/2005 17:30:33
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings8.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:34
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings8.zip;password protected has not been processed;30/06/2005 17:30:34
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings9.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:35
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Roings9.zip;password protected has not been processed;30/06/2005 17:30:35
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ShortyBHO.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:35
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ShortyBHO.zip;password protected has not been processed;30/06/2005 17:30:35
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ShortyBHO1.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ShortyBHO1.zip;password protected has not been processed;30/06/2005 17:30:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant1.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:36
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant10.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:40
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant11.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:42
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant2.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:42
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant3.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant4.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant5.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant6.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip\sac.exe;password protected has not been processed;30/06/2005 17:30:43
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SolutionsSearchAssistant7.zip;password protected has not been processed;30/06/2005 17:30:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TXBrowserAd.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TXBrowserAd.zip;password protected has not been processed;30/06/2005 17:30:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TXBrowserAd1.zip\sbRecovery.reg;password protected has not been processed;30/06/2005 17:30:44
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\TXBrowserAd1.zip;password protected has not been processed;30/06/2005 17:30:45
C:\Documents and Settings\TRegan\Desktop\aawsepersonal.exe/WISE0020.BIN\Ad-Aware SE Default.skn;password protected has not been processed;30/06/2005 17:31:22
C:\Documents and Settings\TRegan\Desktop\aawsepersonal.exe/WISE0020.BIN;password protected has not been processed;30/06/2005 17:31:34
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF10EGLF10E.EXE/WISE0001.BIN;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:31:49
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF10EGLF10E.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF17GLF17.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF17GLF17.EXE;object could not be disinfected;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF17GLF17.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF1EGLF1E.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF1EGLF1E.EXE;object could not be disinfected;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF1EGLF1E.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF2DGLF2D.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF2DGLF2D.EXE;object could not be disinfected;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF2DGLF2D.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF4BGLF4B.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF4BGLF4B.EXE;object could not be disinfected;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF4BGLF4B.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF52GLF52.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF52GLF52.EXE;object could not be disinfected;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF52GLF52.EXE;deleted;30/06/2005 17:32:02
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF75GLF75.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF75GLF75.EXE;object could not be disinfected;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF75GLF75.EXE;deleted;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF83GLF83.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF83GLF83.EXE;object could not be disinfected;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF83GLF83.EXE;deleted;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF91GLF91.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF91GLF91.EXE;object could not be disinfected;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLF91GLF91.EXE;deleted;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE0GLFE0.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE0GLFE0.EXE;object could not be disinfected;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE0GLFE0.EXE;deleted;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE2GLFE2.EXE;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE2GLFE2.EXE;object could not be disinfected;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\GLFE2GLFE2.EXE;deleted;30/06/2005 17:32:03
C:\Documents and Settings\TRegan\Local Settings\Temp\tsinstall_4_0_3_8_b17.exe/WISE0010.BIN;is infected with a virus Trojan-Downloader.Win32.TSUpdate.k;30/06/2005 17:32:04
C:\Documents and Settings\TRegan\Local Settings\Temp\tsinstall_4_0_3_8_b17.exe;deleted;30/06/2005 17:32:05
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\89E30DA7\127062[1].exe;is infected with a virus Trojan-Proxy.Win32.Sobit.e;30/06/2005 17:32:27
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\89E30DA7\127062[1].exe;deleted;30/06/2005 17:32:27
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\OP2FCPUF\optimize314[1].exe;is infected with a virus Trojan-Downloader.Win32.Dyfuca.ei;30/06/2005 17:32:58
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\OP2FCPUF\optimize314[1].exe;deleted;30/06/2005 17:32:58
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\OP2FCPUF\protect[2].htm;is infected with a virus Trojan-Downloader.JS.Codebase.c;30/06/2005 17:32:58
C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\OP2FCPUF\protect[2].htm;deleted;30/06/2005 17:32:58
C:\Program Files\Common Files\fkqq\fkqqa.exe;is infected with a virus Trojan-Downloader.Win32.TSUpdate.l;30/06/2005 17:34:23
C:\Program Files\Common Files\fkqq\fkqqa.exe;deleted;30/06/2005 17:34:23
C:\Program Files\Common Files\fkqq\fkqql.exe;is infected with a virus Trojan-Downloader.Win32.TSUpdate.j;30/06/2005 17:34:23
C:\Program Files\Common Files\fkqq\fkqql.exe;deleted;30/06/2005 17:34:23
C:\Program Files\Internet Explorer\shttps\start.exe;is infected with a virus Trojan-Proxy.Win32.Delf.t;30/06/2005 17:35:11
C:\Program Files\Internet Explorer\shttps\start.exe;deleted;30/06/2005 17:35:11
C:\Program Files\Internet Optimizer\update\optimize314.exe;is infected with a virus Trojan-Downloader.Win32.Dyfuca.ei;30/06/2005 17:35:12
C:\Program Files\Internet Optimizer\update\optimize314.exe;deleted;30/06/2005 17:35:12
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\Ad-Aware SE Default.skn;password protected has not been processed;30/06/2005 17:35:34
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask;password protected has not been processed;30/06/2005 17:35:36
C:\Program Files\WebSiteViewer\127062.dlr;is infected with a virus Trojan-Clicker.Win32.Small.cb;30/06/2005 17:43:22
C:\Program Files\WebSiteViewer\127062.dlr;deleted;30/06/2005 17:43:22
C:\Program Files\WebSiteViewer\127062.exe;is infected with a virus Trojan-Proxy.Win32.Sobit.e;30/06/2005 17:43:22
C:\Program Files\WebSiteViewer\127062.exe;deleted;30/06/2005 17:43:22
C:\WINNT\inst\3p_1.exe;is infected with a virus Trojan-Downloader.Win32.Dyfuca.du;30/06/2005 17:47:57
C:\WINNT\inst\3p_1.exe;deleted;30/06/2005 17:47:57
C:\WINNT\inst\3p_2.exe/WISE0001.BIN;is infected with a virus Trojan-Downloader.Win32.TSUpdate.f;30/06/2005 17:47:57
C:\WINNT\inst\3p_2.exe;deleted;30/06/2005 17:47:57
C:\WINNT\isrvs\delprot.sys;is a Trojan Trojan.Win32.Delprot.a;30/06/2005 17:48:03
C:\WINNT\isrvs\delprot.sys;deleted;30/06/2005 17:48:03
C:\WINNT\isrvs\edmond.exe;is a Trojan Trojan.Win32.Delprot.a;30/06/2005 17:48:03
C:\WINNT\isrvs\edmond.exe;deleted;30/06/2005 17:48:03
C:\WINNT\system32\dload.exe;is infected with a virus Trojan-Downloader.Win32.Delf.dg;30/06/2005 17:49:54
C:\WINNT\system32\dload.exe;deleted;30/06/2005 17:49:54
C:\WINNT\system32\mc-58-12-0000093.exe;is a Trojan Trojan.Win32.Agent.fd;30/06/2005 17:50:12
C:\WINNT\system32\mc-58-12-0000093.exe;deleted;30/06/2005 17:50:12
  • 0

#49
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi Terry,

That looks good, the password protected ones are all in Spybot removed folder and are zipped up. No danger there.

You could always try a different mail client if you can't get office repaired

Thunderbird is good

I'll leave this topic open for a while in case anything develops

From your log, I see nothing in the ways of trojans, nor any evil entities attempting to possess your computer, except for Windows but it's too late for that one. :tazz:

Congratulations your log now appears to be clean. ;)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:

Detect and Remove Programs:
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
Prevention Programs:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
Other necessary Programs:
  • AntiVirus Program<= An AntiVirus program is a must! Whether it is a free version like AVG or Anti-Vir, or a shareware version like Norton or Kapersky, this is a must have.
  • Firewall<= A firewall is definatley a must have. Two good free versions are Sygate and ZoneLabs.
  • More Secure Browser<= Internet Explorer is not the most secure and best browser. There are safer and better alternatives available. I recommend Firefox, however Opera and SlimBrowsers are good as well.
And also see TonyKlein's good advice
So how did I get infected in the first place? and AntiSpyware Net's spyware article: Spyware, Adware, Malware: What it is, how it got on my computer, how to get rid of it, and how to prevent it.
  • 0

#50
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
I hate to break this to you but nothing has changed!.

I still get Spy Sheriff opening up and my desk top and internet use is still being hijacked

I also noticed another program appearing in task manager called desktop search.

Sorry to be the bearer of bad news.

I have got my outlook back however.

Terry
  • 0

#51
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Post a new HJT log.

Run this Online scan

Trend]Trend[/URL] and post the log back
  • 0

#52
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Also go to this site, browse to your c:\winnt\explorer application on your pc and upload it to get it checked by multiple scans. we need to make sure bube has not infected it again. Post the results back

Jotti
  • 0

#53
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi

I cannot get through on the trend site but I will keep trying ,in the meantime I attach a hi jack log

Terry




Logfile of HijackThis v1.99.1
Scan saved at 19:03:58, on 30/06/2005
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP2 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\internat.exe
C:\WINNT\system32\cmd.exe
C:\Program Files\Common Files\services.exe
C:\Program Files\RMClient\PMClient.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Shorty - {11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6} - C:\Program Files\DNS\Catcher.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINNT\isrvs\sysupd.dll (file missing)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINNT\system32\nsh6.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINNT\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINNT\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [fkqq] C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINNT\system32\sex.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SmartNetMonitor for Client.lnk = C:\Program Files\RMClient\PMClient.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.addictivetechnologies.net
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.addictivetechnologies.com (HKLM)
O15 - Trusted Zone: *.addictivetechnologies.net (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.c4tdownload.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.f1organizer.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.megapornix.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.overpro.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.topconverting.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {5938FEB1-3609-11D4-85CD-00902707DAE7} (MapCtl Class) - http://www.promapser...test/webmap.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1118749099296
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = WORTH.local
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINNT\isrvs\mfiltis.dll
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
  • 0

#54
Guest_usetobe_*

Guest_usetobe_*
  • Guest
Hi terry,

Please upgrade to SP4 again, we need to clear up some of the vulnerabilities.

Any luck with the Jotti scan?
  • 0

#55
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi again

Sorry for the delay

Still cannot get onto the Trend site.

Jotti scan attached.


Sorry to be thick but what is SP4?

Terry

File to upload & scan:
Service
Service load: 0% 100%

File: explorer.exe
Status: OK (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 5f3ba74126d0abc8e113d2aeb86b65cf
Packers detected: -
Scanner results
AntiVir Found nothing
ArcaVir Found nothing
Avast Found nothing
AVG Antivirus Found nothing
BitDefender Found nothing
ClamAV Found nothing
Dr.Web Found nothing
F-Prot Antivirus Found nothing
Fortinet Found nothing
Kaspersky Anti-Virus Found nothing
NOD32 Found nothing
Norman Virus Control Found nothing
UNA Found nothing
VBA32 Found nothing

Powered by

Disclaimer
This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, I cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

Also, I am aware of the implications of a setup like this. I am sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). I am aware, in spite of efforts to proactively counter these, false positives might occur, for example. I do not consider this a very big issue, so please do not e-mail me about it. This is a simple online scan service, not the university of Wichita.

Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

Virus definitions are updated every hour. There is a 15Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception.

This service costs me money. Dedicated hosting, undonated scanner licenses etc... If you find this service useful, please consider a (small) donation to help cover expenses.

Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, James Love, Gideon Pertzov, Malcolm Murray, Nigel Thomas, Wendy Dickerson, Anthony Midmore, "ethereal", Mark Rubins, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, and some people who prefer to remain anonymous... many thanks to all!

Statistics
Last file scanned at least one scanner reported something about: Exploit.HTML.CodeBaseExec in Trash, detected by:

Scanner Malware name
AntiVir TR/Expl.Exec.Gen.3
ArcaVir X
Avast X
AVG Antivirus X
BitDefender Exploit.Html.Codebase.Exec.Gen
ClamAV Exploit.ObjCodebase.Calc
Dr.Web Exploit.CodeBase
F-Prot Antivirus X
Fortinet X
Kaspersky Anti-Virus Exploit.HTML.CodeBaseExec
NOD32 X
Norman Virus Control X
UNA X
VBA32 X


You're free to (mis)interpret these automated, flawed statistics at your own discretion.


69516 files (42762 of those unique) have been uploaded & scanned since 07/06/2005, the day of the last database purge.
11849 of those 42762 files contained a virus or any other form of malware.
This page has been visited 108037 times in this time period.
  • 0

Advertisements


#56
Guest_usetobe_*

Guest_usetobe_*
  • Guest
SP4 is service pack 4 from Microsoft

Click here

The good news is that explorer.exe is not infected.

We need to run through the procedure again, to clear out as much as possible before doing deeper scans.

Download the attachment on the bottom of this post to your desktop.
Right click on the file and extract it to it's own folder on the desktop.

Open ewido and update the definitions to the newest files. Do NOT run a scan yet.

Click here to download Pocket Killbox by Option^Explicit. Extract it from the zip file to desktop.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Ad-Aware SE Setup
Don't run it yet!

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Now scan with HJT and place a checkmark next to each of the following items:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Shorty - {11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6} - C:\Program Files\DNS\Catcher.dll
O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINNT\isrvs\sysupd.dll (file missing)
O2 - BHO: ohb - {999A06FF-10EF-4A29-8640-69E99882C26B} - C:\WINNT\system32\nsh6.dll
O4 - HKCU\..\Run: [fkqq] C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINNT\system32\sex.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O15 - Trusted Zone: *.addictivetechnologies.com
O15 - Trusted Zone: *.addictivetechnologies.net
O15 - Trusted Zone: *.awmdabest.com
O15 - Trusted Zone: *.c4tdownload.com
O15 - Trusted Zone: *.clickspring.net
O15 - Trusted Zone: *.crazywinnings.com
O15 - Trusted Zone: *.f1organizer.com
O15 - Trusted Zone: *.frame.crazywinnings.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.megapornix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.overpro.com
O15 - Trusted Zone: *.searchmiracle.com
O15 - Trusted Zone: *.slotch.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.static.topconverting.com
O15 - Trusted Zone: *.topconverting.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.xxxtoolbar.com
O15 - Trusted Zone: *.ysbweb.com
O15 - Trusted Zone: *.addictivetechnologies.com (HKLM)
O15 - Trusted Zone: *.addictivetechnologies.net (HKLM)
O15 - Trusted Zone: *.awmdabest.com (HKLM)
O15 - Trusted Zone: *.c4tdownload.com (HKLM)
O15 - Trusted Zone: *.clickspring.net (HKLM)
O15 - Trusted Zone: *.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.f1organizer.com (HKLM)
O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.megapornix.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: *.overpro.com (HKLM)
O15 - Trusted Zone: *.searchmiracle.com (HKLM)
O15 - Trusted Zone: *.slotch.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.static.topconverting.com (HKLM)
O15 - Trusted Zone: *.topconverting.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted Zone: *.xxxtoolbar.com (HKLM)
O15 - Trusted Zone: *.ysbweb.com (HKLM)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone


Open the smitRem folder from the attachment, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

double-click on Killbox.exe to run it. put a mark next to "Delete on Reboot". Copy and paste each filepath below into the file name box, then click the red button with the X after each. It will ask you if you want to reboot each time you click it, answer NO until after you've pasted the last file name, at which time you should answer Yes.

C:\Program Files\DNS\Catcher.dll
C:\WINNT\isrvs\
C:\WINNT\system32\nsh6.dll
C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe
C:\winstall.exe
C:\Program Files\Common Files\mc-58-12-0000093.exe
C:\Program Files\SpySheriff\SpySheriff.exe
C:\WINNT\system32\sex.exe
C:\WINNT\web\related.htm


If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, click here to download and run missingfilesetup.exe. Then try TheKillbox again.

Whilst your PC is rebooting tap the F8 key to enter SAFE MODE again.

Open Ad-aware and do a full scan. Remove all it finds.

Now open Ewido Security Suite
  • Click on scanner
  • Make sure the following boxes are checked before scanning if active:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean files, click OK
Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save Report
  • Save the report to your desktop
Close Ewido

Next go to Control Panel click Display > Desktop > Customize Desktop > Website > Uncheck "Security Info" if present.

Reboot back into Windows and carry out another Panda ActiveScan. Make sure the autoclean box is checked!
Save the scan log and post it


Please download the free MWAV antivirus tool from here:
ftp://ftp.microworldsystems.com/download/tools/mwav.exe

This scan might take around 3+ hours to finish when set to scan everything. I need you to run MWav, put a check next to below items before scanning:

*Memory
*Startup Folders
*Drive - All Local Drives
*Folder - then click "browse" to change the directory to C: (default is C:\Windows)
*Registry
*System Folders
*Services
*Include Sub-Directory
*Scan All Files

Please make sure ALL of these are checked, then press the scan button. This typically will take hours to complete.

**NOTE*** Sometimes MWav will pause and it appears to be finished, but it isn't done. Just let it run until it says it's complete.

Highlight the portion of the scan that lists infected items and hold CTRL + C to Copy then paste it here. The whole log will be extremely BIG so there is no way to copy the whole thing. I just need the infected items list.

Download Silent Runners
Unzip it to a permanent folder.
Start SilentRunners.vbs
When your antivirus is giving an alert, do not block this. Allow the script.
Copy and paste the content of the txtfile you get afterwards in your next reply.

1.) Download the Hoster from HERE Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Download: [b]http://www.mvps.org/winhelp2002/DelDomains.inf

To use: right-click and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

Now rescan with HJT and post the log back together with all the other requested logs

Attached Files


  • 0

#57
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Phew! finished at last

Unfortunately I could not save the Ewido report. I have no internet connection in safe mode and the file save did not transfer to normal mode.

Attached are all other logs requested

Everything seems ok but I have not yet tried logging out after completion of all steps.



Terry

Panda

Incident Status Location

Spyware:Spyware/BargainBuddy No disinfected C:\WINNT\system32\cache32_rtneg?
Adware:Adware/nCase No disinfected C:\Program Files\180searchassistant
Spyware:Spyware/Dyfuca No disinfected Windows Registry
Adware:Adware/Apropos No disinfected C:\DOCUME~1\TRegan\LOCALS~1\Temp\cfout.txt
Adware:Adware/Sqwire No disinfected Windows Registry
Adware:Adware/ISearch No disinfected C:\WINNT\isrvs
Spyware:Spyware/Media-motor No disinfected Windows Registry
Adware:Adware/Transponder No disinfected C:\WINNT\inst
Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\TRegan\Favorites\1111\1111.url
Adware:Adware/ImGiant No disinfected C:\Program Files\joystick networks
Adware:Adware/SpywareNo No disinfected Windows Registry
Adware:Adware/Pacimedia No disinfected C:\Documents and Settings\TRegan\Favorites\1111\1111.url
Adware:Adware/Beginto No disinfected C:\Documents and Settings\TRegan\Local Settings\Temporary Internet Files\Content.IE5\0AQ64NLG\sp[1].js
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\FreeProdFetch\mc-58-12-0000093.exe
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\services.exe
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\system32.dll
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\system32.dll[Catcher.dll]
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\system32.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\Program Files\DNS\gui.exe
Adware:Adware/Maxifiles No disinfected C:\Program Files\HJT\backups\backup-20050628-183604-738.dll
Adware:Adware/Maxifiles No disinfected C:\Program Files\HJT\backups\backup-20050629-102516-911.dll
Adware:Adware/Maxifiles No disinfected C:\Program Files\HJT\backups\backup-20050704-173438-696.dll
Adware:Adware/Sqwire No disinfected C:\RECYCLER\S-1-5-21-507921405-1708537768-839522115-500\Dc1\fkqqd\fkqqc.dll
Adware:Adware/ISearch No disinfected C:\WINNT\delprot.ini
Adware:Adware/ISearch No disinfected C:\WINNT\deskbar.ini
Adware:Adware/ISearch No disinfected C:\WINNT\isrvs\isearch.xpi
Adware:Adware/ISearch No disinfected C:\WINNT\isrvs\isearch.xpi[isearch.jar][isearch.js]
Adware:Adware/Sqwire No disinfected C:\WINNT\system32\tsuninst.exe
MWAV

ue Jul 05 09:21:20 2005 => ***** Scanning Registry and File system for Adware/Spyware *****
Tue Jul 05 09:21:50 2005 => System found infected with SexList Spyware/Adware (_{CFBFAE00-17A6-11D0-99CB-00C04FD64497})! Action taken: No Action Taken.
Tue Jul 05 09:21:50 2005 => Object "SexList Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:21:51 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken.
Tue Jul 05 09:21:51 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:21:52 2005 => System found infected with Alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Jul 05 09:21:52 2005 => Object "Alexa Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:03 2005 => Offending value found in HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\power scan !!!
Tue Jul 05 09:22:03 2005 => Object "Power scan Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:05 2005 => Offending value found in HKCU\Software\Microsoft\Windows\CurrentVersion\policies\ameopt !!!
Tue Jul 05 09:22:05 2005 => Object "ameopt Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:05 2005 => Offending value found in HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\tsa !!!
Tue Jul 05 09:22:05 2005 => Offending value found in HKCU\Software\tsa !!!
Tue Jul 05 09:22:05 2005 => Object "tsa Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:06 2005 => Offending value found in HKCU\Software\avenue media !!!
Tue Jul 05 09:22:06 2005 => Offending value found in HKCU\Software\policies\avenue media !!!
Tue Jul 05 09:22:06 2005 => Object "180Solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:07 2005 => Offending Folder C:\PROGRA~1\180SEA~1 present...
Tue Jul 05 09:22:07 2005 => Object "180Solutions Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:17 2005 => Offending value found in HKCU\Software\WebSiteViewer !!!
Tue Jul 05 09:22:17 2005 => Offending Folder C:\PROGRA~1\WEBSIT~1 present...
Tue Jul 05 09:22:17 2005 => Object "WebSiteViewer Spyware/Adware" found in File System! Action Taken: No Action Taken.

Tue Jul 05 09:22:38 2005 => System found infected with iSearch Spyware/Adware (patch.exe)! Action taken: No Action Taken.
Tue Jul 05 09:22:38 2005 => Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.


Tue Jul 05 09:22:38 2005 => ***** Scanning Registry for errors created because of Adware/Spyware *****
Tue Jul 05 09:22:38 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\Downloaded Program Files\CONFLICT.1\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:38 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\Downloaded Program Files\CONFLICT.2\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:38 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\Downloaded Program Files\internazionale_ver11.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\Downloaded Program Files\m67m.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\Downloaded Program Files\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINNT\System32\objsafe.tlb". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\logo.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\scribble.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\dot.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\mnature.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\hoverbot.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\will.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\powerpup.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:39 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "D:\Office\Actors\genius.act". Action Taken: No Action Taken.

Tue Jul 05 09:22:40 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\Downloaded Program Files\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:40 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\System32\objsafe.tlb". Action Taken: No Action Taken.

Tue Jul 05 09:22:40 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\Downloaded Program Files\internazionale_ver11.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:41 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\Downloaded Program Files\CONFLICT.1\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:41 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\Downloaded Program Files\CONFLICT.2\ysbactivex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:41 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINNT\Downloaded Program Files\m67m.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:41 2005 => Entry "HKCR\CLSID\{00020D05-0000-0000-C000-000000000046}" refers to invalid object "outex.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:42 2005 => Entry "HKCR\CLSID\{079aa557-4a18-424a-8eee-e39f0a8d41b9}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{2933BF90-7B36-11d2-B20E-00C04F983E60}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{2933BF91-7B36-11d2-B20E-00C04F983E60}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{2933BF94-7B36-11d2-B20E-00C04F983E60}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{3124c396-fb13-4836-a6ad-1317f1713688}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{31B6081F-7590-4A18-BEDF-E938294031D8}" refers to invalid object "C:\WINNT\System32\laca.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{373984C9-B845-449B-91E7-45AC83036ADE}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:44 2005 => Entry "HKCR\CLSID\{379E501F-B231-11d1-ADC1-00805FC752D8}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:45 2005 => Entry "HKCR\CLSID\{3d813dfe-6c91-4a4e-8f41-04346a841d9c}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:45 2005 => Entry "HKCR\CLSID\{3e784a01-f3ae-4dc0-9354-9526b9370eba}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:45 2005 => Entry "HKCR\CLSID\{4419DD31-28A5-11d2-AE08-0080C7337EA1}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:45 2005 => Entry "HKCR\CLSID\{48123bc4-99d9-11d1-a6b3-00c04fd91555}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:46 2005 => Entry "HKCR\CLSID\{4dd441ad-526d-4a77-9f1b-9841ed802fb0}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:46 2005 => Entry "HKCR\CLSID\{550dda30-0541-11d2-9ca9-0060b0ec3d39}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:46 2005 => Entry "HKCR\CLSID\{57B4B693-2388-11d3-8E39-0080C7ACC199}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:47 2005 => Entry "HKCR\CLSID\{5F3E04C3-4612-11D0-A113-00A024B50363}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAREG.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:47 2005 => Entry "HKCR\CLSID\{5F3E04C4-4612-11D0-A113-00A024B50363}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAMDMTR.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:47 2005 => Entry "HKCR\CLSID\{5F3E04C6-4612-11D0-A113-00A024B50363}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAREG.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:47 2005 => Entry "HKCR\CLSID\{649D583D-3401-11D1-8C47-0080C7C43E7F}" refers to invalid object "C:\Program Files\Microsoft Office\Office\1033\WFXRSTRZ.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:48 2005 => Entry "HKCR\CLSID\{7149E79C-DC19-4C5E-A53C-A54DDF75EEE9}" refers to invalid object "C:\WINNT\Downloaded Program Files\m67m.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:48 2005 => Entry "HKCR\CLSID\{77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F}" refers to invalid object "C:\Program Files\Maxifiles\maxifiles.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:48 2005 => Entry "HKCR\CLSID\{79eac9c3-baf9-11ce-8c82-00aa004ba90b}" refers to invalid object "C:\WINNT\System32\hlinkprx.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:48 2005 => Entry "HKCR\CLSID\{7B49476B-CD0C-4D16-95D5-FE49CA3C8CAB}" refers to invalid object "C:\WINNT\System32\laca.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:48 2005 => Entry "HKCR\CLSID\{7E3FCEA1-31B4-11d2-AE1F-0080C7337EA1}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:49 2005 => Entry "HKCR\CLSID\{800DD100-DB43-11CE-914E-00A004000162}" refers to invalid object "C:\Program Files\Microsoft Office\Office\msspc32.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:50 2005 => Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:50 2005 => Entry "HKCR\CLSID\{A4845882-333F-11D0-B724-00AA0062CBB7}" refers to invalid object "C:\WINNT\System32\WBEM\WBEMSTUB.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:50 2005 => Entry "HKCR\CLSID\{AB481080-796C-11D0-A113-00A024B50363}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAABOUT.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:51 2005 => Entry "HKCR\CLSID\{afb40ffd-b609-40a3-9828-f88bbe11e4e3}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:51 2005 => Entry "HKCR\CLSID\{afba6b42-5692-48ea-8141-dc517dcf0ef1}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:51 2005 => Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.

Tue Jul 05 09:22:51 2005 => Entry "HKCR\CLSID\{BC54B24C-5A97-4C19-9181-8B8A05B2E931}" refers to invalid object "C:\WINNT\System32\nso123.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:51 2005 => Entry "HKCR\CLSID\{BD9584EF-C28C-4F6D-8D49-0CEE3C0E442F}" refers to invalid object "C:\WINNT\System32\nso123.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:52 2005 => Entry "HKCR\CLSID\{C1172D01-751C-11D0-B6CF-00A024BF23EF}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRASRIAL.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:52 2005 => Entry "HKCR\CLSID\{C7888681-1A83-4C14-B9A5-95F91240B44F}" refers to invalid object "C:\WINNT\System32\nso123.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:52 2005 => Entry "HKCR\CLSID\{CCDD9080-8100-11D0-B6CF-00A024BF23EF}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRALPTTR.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:53 2005 => Entry "HKCR\CLSID\{CFC399AF-D876-11d0-9C10-00C04FC99C8E}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:53 2005 => Entry "HKCR\CLSID\{D19781C5-2051-44F8-8445-DDC82933C191}" refers to invalid object "C:\WINNT\Downloaded Program Files\internazionale_ver11.ocx". Action Taken: No Action Taken.

Tue Jul 05 09:22:53 2005 => Entry "HKCR\CLSID\{d2423620-51a0-11d2-9caf-0060b0ec3d39}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:53 2005 => Entry "HKCR\CLSID\{DA6A85E0-05C7-11D1-B243-006097CAD7E2}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAABOUT.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:53 2005 => Entry "HKCR\CLSID\{E07D3492-32B5-11D0-B724-00AA0062CBB7}" refers to invalid object "C:\WINNT\System32\WBEM\WBEMSTUB.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:54 2005 => Entry "HKCR\CLSID\{E3DA8715-3769-4DCE-BCB4-A7391412B495}" refers to invalid object "C:\WINNT\System32\laca.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:54 2005 => Entry "HKCR\CLSID\{E5B42981-67DC-11D0-8547-00A0240B50F0}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAWEBTR.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:54 2005 => Entry "HKCR\CLSID\{E8D83F00-CD78-11D0-B4D3-00A024BF23EF}" refers to invalid object "C:\PROGRA~1\COMMON~1\IRAABOUT.DLL". Action Taken: No Action Taken.

Tue Jul 05 09:22:54 2005 => Entry "HKCR\CLSID\{ED8C108E-4349-11D2-91A4-00C04F7969E8}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f19-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f27-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f31-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f32-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f33-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f34-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f35-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f36-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f37-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f39-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f3f-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f40-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{f5078f41-c551-11d3-89b9-0000f81fe221}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{F6D90F12-9C73-11D3-B32E-00C04F990BB4}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{F6D90F14-9C73-11D3-B32E-00C04F990BB4}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:55 2005 => Entry "HKCR\CLSID\{F6D90F16-9C73-11D3-B32E-00C04F990BB4}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:22:56 2005 => Entry "HKCR\CLSID\{fc220ad8-a72a-4ee8-926e-0b7ad152a020}" refers to invalid object "%SystemRoot%\system32\msxml3.dll". Action Taken: No Action Taken.

Tue Jul 05 09:23:00 2005 => Entry "HKCR\btnetw.ohb" refers to invalid object "{9ADE0443-2AB2-4B23-A3F8-AC520773DE12}". Action Taken: No Action Taken.

Tue Jul 05 09:23:00 2005 => Entry "HKCR\btnetw.ohb.1" refers to invalid object "{9ADE0443-2AB2-4B23-A3F8-AC520773DE12}". Action Taken: No Action Taken.

Tue Jul 05 09:23:05 2005 => Entry "HKCR\LowSol.RichEditor" refers to invalid object "{F79A2C4B-8776-4ED7-8B2F-4786A4A3500A}". Action Taken: No Action Taken.

Tue Jul 05 09:23:05 2005 => Entry "HKCR\LowSol.RichEditor.1" refers to invalid object "{F79A2C4B-8776-4ED7-8B2F-4786A4A3500A}". Action Taken: No Action Taken.

Tue Jul 05 09:23:09 2005 => Entry "HKCR\ncmyb.SABHO" refers to invalid object "{21B4ACC4-8874-4AEC-AEAC-F567A249B4D4}". Action Taken: No Action Taken.

Tue Jul 05 09:23:09 2005 => Entry "HKCR\ncmyb.SABHO.1" refers to invalid object "{21B4ACC4-8874-4AEC-AEAC-F567A249B4D4}". Action Taken: No Action Taken.

Tue Jul 05 09:23:10 2005 => Entry "HKCR\Photoshop.Application.4" refers to invalid object "{6DECC242-87EF-11cf-86B4-444553540000} ". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\Shorty.Gopher" refers to invalid object "{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6}". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\Shorty.Gopher.1" refers to invalid object "{11A4CA8C-A8B9-49c2-A6D3-3F64C9EEBAE6}". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\ToolBand.XBTB07618" refers to invalid object "{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\ToolBand.XBTB07618.1" refers to invalid object "{BBBE1C1A-89F7-4AF6-ABD1-F8FBCFA47408}". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\VBRun.VBRunDLL" refers to invalid object "{197B8CA4-E215-46DD-8F33-E0544A80E5C4}". Action Taken: No Action Taken.

Tue Jul 05 09:23:12 2005 => Entry "HKCR\VBRun.VBRunDLL.1" refers to invalid object "{197B8CA4-E215-46DD-8F33-E0544A80E5C4}". Action Taken: No Action Taken.


Silent Runners

"Silent Runners.vbs", revision 39, http://www.silentrunners.org/
Operating System: Windows 2000
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"internat.exe" = "internat.exe" [MS]
"fkqq" = "C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe" [file not found]
"Windows installer" = "C:\winstall.exe" [file not found]
"DNS" = "C:\Program Files\Common Files\mc-58-12-0000093.exe" [file not found]
"SpySheriff" = "C:\Program Files\SpySheriff\SpySheriff.exe" [file not found]
"Windows Service" = "C:\WINNT\system32\sex.exe" [file not found]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"Synchronization Manager" = "mobsync.exe /logon" [MS]
"JobHisInit" = "C:\Program Files\RMClient\JobHisInit.exe" [empty string]
"MplSetUp" = "C:\Program Files\RMClient\MplSetUp.exe" ["RICOH CO.,LTD."]
"KAVPersonal50" = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize" ["Kaspersky Lab"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> {CLSID}\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> {CLSID}\InProcServer32\(Default) = "C:\WINNT\System32\hticons.dll" ["Hilgraeve, Inc."]
"{0006F045-0000-0000-C000-000000000046}" = "Microsoft Outlook Custom Icon Handler"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\Office\OLKFSTUB.DLL" [MS]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
INFECTION WARNING! "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" = "ewido shell guard"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\shellhook.dll" ["TODO: <Firmenname>"]

HKLM\System\CurrentControlSet\Control\Session Manager\
INFECTION WARNING! "BootExecute" = "autocheck autochk * sprestrt" [file not found], [MS], [file not found], [MS]

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
ewido\(Default) = "{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\ewido\security suite\context.dll" ["ewido networks"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
Kaspersky Anti-Virus\(Default) = "{dd230880-495a-11d1-b064-008048ec2fc5}"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\shellex.dll" ["Kaspersky Lab"]
WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]


Group Policies [Description] {enabled Group Policy setting}:
------------------------------------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
HIJACK WARNING! "ForceActiveDesktopOn"=dword:00000001
[enables Active Desktop and prevents disabling it]
{User Configuration|Administrative Templates|Desktop|Active Desktop|
Enable Active Desktop}

HIJACK WARNING! "Wallpaper" = "C:\WINNT\desktop.html"
[disables Display Properties|Background (tab); selects wallpaper if
Active Desktop is enabled]
{User Configuration|Administrative Templates|Desktop|Active Desktop|
Active Desktop Wallpaper|Wallpaper Name:}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop enabled via Group Policy.

Wallpaper selected via Group Policy.


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\

HKCU\Software\Microsoft\Internet Explorer\Desktop\Components\0\
"SCRNSAVE.EXE" = "C:\WINNT\System32\sspipes.scr" [MS]


Startup items in "tregan" & "All Users" startup folders:
--------------------------------------------------------

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
"Microsoft Office" -> shortcut to: "C:\Program Files\Microsoft Office\Office\OSA9.EXE -b -l" [MS]
"SmartNetMonitor for Client" -> shortcut to: "C:\Program Files\RMClient\PMClient.exe" ["RICOH COMPANY,LTD."]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\rnr20.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]

Transport Service Providers

HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
%SystemRoot%\system32\msafd.dll [MS], 01 - 03, 06 - 11
%SystemRoot%\system32\rsvpsp.dll [MS], 04 - 05


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll" ["Yahoo! Inc."]

HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Companion" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll" ["Yahoo! Inc."]

Extensions (Tools menu items, main toolbar menu buttons)

HKLM\Software\Microsoft\Internet Explorer\Extensions\
{85D1F590-48F4-11D9-9669-0800200C9A66}\
"MenuText" = "Uninstall BitDefender Online Scanner v8"
"Exec" = "%windir%\bdoscandel.exe" [null data]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

C-DillaSrv, C-DillaSrv, "C:\WINNT\system32\DRIVERS\CDANTSRV.EXE" ["C-Dilla Ltd"]
ewido security suite control, ewido security suite control, "C:\Program Files\ewido\security suite\ewidoctrl.exe" ["ewido networks"]
kavsvc, kavsvc, "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe" ["Kaspersky Lab"]


----------
+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
+ The search for DESKTOP.INI DLL launch points on all local fixed drives
took 23 seconds.
+ The search for all Registry CLSIDs containing dormant Explorer Bars
took 10 seconds.
---------- (total run time: 76 seconds)
HiJack
Logfile of HijackThis v1.99.1
Scan saved at 11:11:55, on 05/07/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\internat.exe
C:\Program Files\RMClient\PMClient.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [fkqq] C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINNT\system32\sex.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SmartNetMonitor for Client.lnk = C:\Program Files\RMClient\PMClient.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {5938FEB1-3609-11D4-85CD-00902707DAE7} (MapCtl Class) - http://www.promapser...test/webmap.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1118749099296
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = WORTH.local
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
  • 0

#58
Justin

Justin

    I do a little bit of everything

  • Member
  • PipPipPipPipPip
  • 2,353 posts
Hello TerryR,

Usetobe has had a Medical Emergency and he has asked me to take care of some of his active topics.

I have noticed that you still have spysheriff on your computer. I know that you have done this at least twice already, but I am goin to have you run the spysheriff fix one more time, hopefully now that explorer.exe is not infected, it will work.

First, download and install CleanUp! but do not run it yet.
*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Download, install, and update Ewido Security Suite
  • Install ewido security suite
  • Launch ewido, there should be a big E icon on your desktop, double-click it.
  • The program will prompt you to update click the OK button
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Click on Start
The update will start and a progress bar will show the updates being installed.
After the updates are installed, exit Ewido

Reboot into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Once in Safe Mode, Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
*Click "Options..."
*Move the arrow down to "Custom CleanUp!"
*Put a check next to the following:
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Scan local drives for temporary files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

After Cleanup! is finished:
  • Run Ewido.
  • Click on scanner
  • Make sure the following boxes are checked before scanning:
    • Binder
    • Crypter
    • Archives
  • Click on Start Scan
  • Let the program scan the machine
While the scan is in progress you will be prompted to clean the first infected file it finds. Choose "clean", then put a check next to "Perform action on all infections" in the left corner of the box so you don't have to sit and watch Ewido the whole time. Click OK.

Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report
  • Save the report to your desktop
  • Exit Ewido
Reboot into normal mode.

Go to Start > Control Panel > Add or Remove Programs and remove the following:

SpySheriff

Exit Add or Remove Programs.

Delete the following, in bold, if found:

C:\Documents and Settings\user account\Start Menu\Programs\SpySheriff <-whole folder
C:\Documents and Settings\user account\Application Data\Install.dat
C:\Program Files\SpySheriff <-whole folder
C:\Windows\Desktop.html
C:\winstall.exe

*NOTE* user account is not the actual name of that folder. The name of that folder will be the name of your computer profile.

Make sure you are disconnected from the Internet and that all programs and windows are closed. Run HiJackThis. Place a check next to the following items, if found, and click FIX CHECKED:

R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O4 - HKCU\..\Run: [Windows installer] C:\winstall.exe
O4 - HKCU\..\Run: [DNS] C:\Program Files\Common Files\mc-58-12-0000093.exe
O4 - HKCU\..\Run: [SpySheriff] C:\Program Files\SpySheriff\SpySheriff.exe
O4 - HKCU\..\Run: [Windows Service] C:\WINNT\system32\sex.exe
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone


Close HiJackThis.

RIGHT-CLICK HERE and go to Save As (in IE it's "Save Target As") in order to download the smitfraud reg to your desktop.

Double-click smitfraud.reg on your desktop. When asked if you want to merge with the registry click YES.

After the merged successfully prompt, using Windows Explorer, navigate to the following folder:

C:\Windows\Prefetch

If there are any files inside the Prefetch folder, delete ALL of them. (Do NOT delete the folder. Just delete the files inside.)

Reboot your computer.

You should be able to change your desktop back to normal now.

Post the report from Ewido and a new HiJackThis log into this topic.

Please let me know if you have any questions.
  • 0

#59
TerryR

TerryR

    Member

  • Topic Starter
  • Member
  • PipPip
  • 31 posts
Hi Justin

Sorry to hear about ustobe hope everthing turns out ok

I tried to follow your instructions with the following results

In Cleanup the delete prefetch files was greyed out and I could not check it

I cannot post the Ewido report. To get into safe mode I have to log on as administrator and whatever I try the reports do not appear in normal mode. If I log on as administrator in normal mode I do not have an internet connection

Spy Sheriff did not appear in start/remove progs.

Explorer could not find the Prefetch folder

Hijack log attached

I have reset my desktop and everything seems to be ok so far.

Terry

Logfile of HijackThis v1.99.1
Scan saved at 13:51:58, on 06/07/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\internat.exe
C:\Program Files\RMClient\PMClient.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Common Files\System\MAPI\1033\nt\MAPISP32.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe

O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [JobHisInit] C:\Program Files\RMClient\JobHisInit.exe
O4 - HKLM\..\Run: [MplSetUp] C:\Program Files\RMClient\MplSetUp.exe
O4 - HKLM\..\Run: [KAVPersonal50] C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe /minimize
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - HKCU\..\Run: [fkqq] C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SmartNetMonitor for Client.lnk = C:\Program Files\RMClient\PMClient.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....467&clcid=0x409
O16 - DPF: {5938FEB1-3609-11D4-85CD-00902707DAE7} (MapCtl Class) - http://www.promapser...test/webmap.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1118749099296
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) - http://support.f-sec...m/ols/fscax.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = WORTH.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = WORTH.local
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: kavsvc - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
  • 0

#60
Justin

Justin

    I do a little bit of everything

  • Member
  • PipPipPipPipPip
  • 2,353 posts
Terry,

That is good when things are not found, it means that most of the infection is gone. The important part of that fix was the smitfraud.reg.

Do you have complete control of your desktop now?

There is one file that keeps coming back. Lets delete it in HiJackThis one more time, and if it comes back we will get rid of it a different way.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O4 - HKCU\..\Run: [fkqq] C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe

Now close all windows other than HiJackThis, then click Fix Checked. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please delete these files using Windows Explorer(if present):

C:\PROGRA~1\COMMON~1\fkqq\fkqqm.exe

After that, Reboot.

Then post a new HiJackThis log for me to look at
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP