Ok here is the log from AVG
S T Virus name Path Date of detection Filename File size
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0025129.CPY 6/20/2005 2:26:40 PM A0025129.CPY 164.5 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0025129.CPY 6/20/2005 2:27:19 PM A0025129.CPY 164.5 KB
Trojan horse Downloader.Small.44.BW C:\WINDOWS\TEMP\WUPDT.EXE 6/20/2005 11:01:41 PM WUPDT.EXE 33 KB
Trojan horse Downloader.Small.44.BW C:\WINDOWS\TEMP\WUPDT.EXE 6/20/2005 11:10:50 PM WUPDT.EXE 33 KB
Trojan horse Downloader.Small.44.BW C:\WINDOWS\TEMP\WUPDT.EXE 6/21/2005 12:25:56 AM WUPDT.EXE 33 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/21/2005 9:10:02 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.44.BW C:\WINDOWS\TEMP\WUPDT.EXE 6/21/2005 9:25:00 PM WUPDT.EXE 33 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/21/2005 9:57:59 PM UCI.EXE 218 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\ASMS.EXE 6/21/2005 9:59:21 PM ASMS.EXE 223.5 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0028630.CPY 6/21/2005 10:21:02 PM A0028630.CPY 164.5 KB
Trojan horse Dropper.Agent.7.K C:\_RESTORE\TEMP\A0028633.CPY 6/21/2005 10:21:02 PM A0028633.CPY 196 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0028771.CPY 6/21/2005 10:21:02 PM A0028771.CPY 218 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0028774.CPY 6/21/2005 10:21:02 PM A0028774.CPY 223.5 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0027632.CPY 6/21/2005 10:21:03 PM A0027632.CPY 164.5 KB
Trojan horse Dropper.Agent.7.K C:\_RESTORE\TEMP\A0027635.CPY 6/21/2005 10:21:03 PM A0027635.CPY 196 KB
Trojan horse Downloader.Small.15.BS C:\_RESTORE\TEMP\A0027638.CPY 6/21/2005 10:21:03 PM A0027638.CPY 57 KB
Trojan horse Downloader.Apropo.AI C:\_RESTORE\TEMP\A0027699.CPY 6/21/2005 10:21:03 PM A0027699.CPY 244 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/21/2005 10:26:47 PM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F288585.EXE 6/21/2005 10:27:22 PM F288585.EXE 117.5 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/21/2005 10:27:50 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/21/2005 10:28:55 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/21/2005 10:29:59 PM UCI.EXE 218 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/21/2005 11:21:42 PM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/21/2005 11:22:50 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/21/2005 11:23:53 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/21/2005 11:24:59 PM UCI.EXE 218 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\ASMS.EXE 6/21/2005 11:26:02 PM ASMS.EXE 223.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/22/2005 12:48:13 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Downloader.Generic.RR C:\WINDOWS\TEMPORARY INTERNET FILES\CONTENT.IE5\KDYRC9Y3\2.8.7.4[1].EXE 6/22/2005 1:15:24 PM 2.8.7.4[1].EXE 64 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/22/2005 10:30:32 PM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\IM49.EXE 6/22/2005 10:31:24 PM IM49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/22/2005 10:32:26 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/22/2005 10:33:35 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/22/2005 10:37:09 PM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\IM49.EXE 6/22/2005 10:37:53 PM IM49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/22/2005 10:38:56 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/22/2005 10:40:01 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F300381.EXE 6/22/2005 10:40:34 PM F300381.EXE 117.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\IM49.EXE 6/22/2005 11:06:21 PM IM49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/22/2005 11:07:23 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/22/2005 11:08:25 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F296691.EXE 6/22/2005 11:09:00 PM F296691.EXE 117.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/23/2005 8:44:49 AM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/23/2005 8:45:58 AM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\IM49.EXE 6/23/2005 8:47:00 AM IM49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/23/2005 8:48:13 AM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F1591221.EXE 6/23/2005 8:48:42 AM F1591221.EXE 117.5 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/23/2005 8:49:08 AM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/23/2005 8:57:05 AM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\IM49.EXE 6/23/2005 8:57:59 AM IM49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/23/2005 8:59:05 AM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/23/2005 9:00:33 AM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/23/2005 9:01:09 AM UCI.EXE 218 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/23/2005 9:02:16 AM UCI.EXE 218 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/24/2005 2:38:02 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/24/2005 2:39:02 PM UCI.EXE 218 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/24/2005 4:08:48 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\WRAPPEROUTER.EXE 6/24/2005 5:33:32 PM WRAPPEROUTER.EXE 164.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\INSTALLER_MARKETING49.EXE 6/24/2005 5:33:54 PM INSTALLER_MARKETING49.EXE 62 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\SSK3_B5 SEEDCORN 4.EXE 6/24/2005 5:35:00 PM SSK3_B5 SEEDCORN 4.EXE 57 KB
Trojan horse Dropper.Agent.7.K C:\WINDOWS\SYSTEM\VENTURA5.EXE 6/24/2005 5:36:19 PM VENTURA5.EXE 196 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F287842.EXE 6/24/2005 5:36:36 PM F287842.EXE 117.5 KB
Trojan horse Downloader.Small.15.BS C:\WINDOWS\SYSTEM\UCI.EXE 6/24/2005 5:37:06 PM UCI.EXE 218 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F17089739.EXE 6/24/2005 10:16:37 PM F17089739.EXE 117.5 KB
Trojan horse Downloader.Generic.RR C:\WINDOWS\TEMP\tp7543.exe 6/25/2005 8:25:24 AM tp7543.exe 64 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F59573810.EXE 6/25/2005 10:04:37 AM F59573810.EXE 117.5 KB
Trojan horse Downloader.Generic.VF C:\WINDOWS\TEMP\F285870.EXE 6/25/2005 11:33:17 AM F285870.EXE 117.5 KB
Here is the Silent Runner Log..............
"Silent Runners.vbs", revision 38.1,
http://www.silentrunners.org/Operating System: Windows Me (Millennium Edition)
Output limited to non-default values, except where indicated by "{++}"
Startup items buried in registry:
---------------------------------
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"MoneyAgent" = ""C:\Program Files\Microsoft Money\System\Money Express.exe"" [MS]
"Taskbar Display Controls" = "RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY" [MS]
"CAS Client" = ""C:\Program Files\Cas\Client\casclient.exe"" [null data]
"Spyware Doctor" = ""C:\PROGRAM FILES\SPYWARE DOCTOR\SWDOCTOR.EXE" /Q" [file not found]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ScanRegistry" = "C:\WINDOWS\scanregw.exe /autorun" [MS]
"TaskMonitor" = "C:\WINDOWS\taskmon.exe" [MS]
"PCHealth" = "C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s" [MS]
"SystemTray" = "SysTray.Exe" [MS]
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"Keyboard Manager" = "C:\Program Files\Netropa\One-touch Multimedia Keyboard\MMKeybd.exe" ["Netropa Corp."]
"HPScanPatch" = "C:\WINDOWS\SYSTEM\HPScanFix.exe" ["Hewlett-Packard Company"]
"MMTray" = (empty string)
"hpsysdrv" = "c:\windows\system\hpsysdrv.exe" ["Hewlett-Packard Company"]
"Delay" = "C:\WINDOWS\delayrun.exe" [file not found]
"LexStart" = "Lexstart.exe" ["Lexmark International, Inc."]
"AVG7_CC" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGCC.EXE /STARTUP" ["GRISOFT, s.r.o."]
"AVG7_EMC" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGEMC.EXE" ["GRISOFT, s.r.o."]
"AVG7_AMSVR" = "C:\PROGRA~1\GRISOFT\AVGFRE~1\AVGAMSVR.EXE" ["GRISOFT, s.r.o."]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ {++}
"LoadPowerProfile" = "Rundll32.exe powrprof.dll,LoadCurrentPwrScheme" [MS]
"SchedulingAgent" = "mstask.exe" [MS]
"SSDPSRV" = "C:\WINDOWS\SYSTEM\ssdpsrv.exe" [MS]
"*StateMgr" = "C:\WINDOWS\System\Restore\StateMgr.exe" [MS]
"StillImageMonitor" = "C:\WINDOWS\SYSTEM\STIMON.EXE" [MS]
"KB891711" = "C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE" [MS]
HKLM\Software\Microsoft\Active Setup\Installed Components\
PerUser_CVT_Inis\(Default) = "Windows Setup - FAT32 Converter"
\StubPath = "rundll.exe C:\WINDOWS\SYSTEM\setupx.dll,InstallHinfSection PerUser_CVT_Inis 64 C:\WINDOWS\INF\applets1.inf" [MS]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = "AcroIEHlprObj Class" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL" ["Adobe Systems Incorporated"]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{e57ce731-33e8-4c51-8354-bb4de9d215d1}" = "Universal Plug and Play Devices"
-> {CLSID}\InProcServer32\(Default) = "C:\WINDOWS\SYSTEM\UPNPUI.DLL" [MS]
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Shell Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}" = "AVG7 Find Extension"
-> {CLSID}\InProcServer32\(Default) = "C:\Program Files\Grisoft\AVG Free\avgse.dll" ["GRISOFT, s.r.o."]
"{34507538-708C-48FF-BA78-1FFDDF0FF3FA}" = "Twister scan shell extension"
-> {CLSID}\InProcServer32\(Default) = "blank" [file not found]
Active Desktop and Wallpaper:
-----------------------------
Active Desktop is enabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "C:\My Documents\tower kids.jpg"
Startup items in "Startup" & "All Users...Startup" folders:
-----------------------------------------------------------
C:\WINDOWS\Start Menu\Programs\StartUp
"Dexxa Optical Mouse" -> shortcut to: "C:\Program Files\Dexxa Optical Mouse\scw64.exe" ["("]
"Sprint FastConnect virtual assistant" -> shortcut to: "C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe -boot" ["Motive Communications, Inc."]
Enabled Scheduled Tasks:
------------------------
"Tune-up Application Start" -> launches: "walign" [MS]
"PCHealth Scheduler for Data Collection" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [MS]
"Maintenance-Defragment programs" -> launches: "C:\WINDOWS\DEFRAG.EXE /SAGERUN:0" [MS]
"Maintenance-ScanDisk" -> launches: "C:\WINDOWS\SCANDSKW.EXE /SAGERUN:0 /ALL /N" [MS]
"Maintenance-Disk cleanup" -> launches: "C:\WINDOWS\CLEANMGR.EXE /SAGERUN:0" [MS]
Winsock2 Service Provider DLLs:
-------------------------------
Namespace Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "C:\WINDOWS\SYSTEM\rnr20.dll" [MS]
Transport Service Providers
HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
00000000000#\PackedCatalogItem (contains) DLL [Company Name], (at) # range:
C:\WINDOWS\SYSTEM\mswsosp.dll [MS], 1
C:\WINDOWS\SYSTEM\msafd.dll [MS], 2 - 4
C:\WINDOWS\SYSTEM\rsvpsp.dll [MS], 5 - 6
Toolbars, Explorer Bars, Extensions:
------------------------------------
Toolbars
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
HKLM\Software\Microsoft\Internet Explorer\Toolbar\
"{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = "Yahoo! Toolbar" [from CLSID]
-> {CLSID}\InProcServer32\(Default) = "C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN2\YCOMP5_6_2_0.DLL" ["Yahoo! Inc."]
Extensions (Tools menu items, main toolbar menu buttons)
HKLM\Software\Microsoft\Internet Explorer\Extensions\
{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "MSN Messenger Service"
"Exec" = "C:\PROGRA~1\MESSEN~1\MSMSGS.EXE" [MS]
Miscellaneous IE Hijack Points
------------------------------
C:\WINDOWS\INF\IERESET.INF (used to "Reset Web Settings")
Added lines (compared with English-language version):
[Strings]: START_PAGE_URL=http://hp.my.yahoo.com
[Strings]: MS_START_PAGE_URL="
http://www.microsoft...5.5&ar=msnhome"Missing lines (compared with English-language version):
[Strings]: 2 lines
----------
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
----------
And the F-Secure Log....................
Finished: 1 virus found
Scanned files: 42368 Warning: 1 file(s) still infected!
c:\Recycled\Dc6.dll Trojan-Downloader.Win32.Qoologic.p
I noticed this was in my recycled so I went ahead and emptied it. I will check back a bit later and see if you have made any sense out of this mess. Thanks again - Andrew