Seems to be clean, I dont have any more pop-ups. I will report back in a day or two.
Here are my logs. Let me know if you see something I missed. Thanks
Logfile of HijackThis v1.99.1
Scan saved at 10:24:28 PM, on 7/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\HJT\HijackThis.exe
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
F2 - REG:system.ini: UserInit=c:\windows\system32\userinit.exe
O2 - BHO: (no name) - {0AD937E7-2F37-4873-A05E-548A67EF1D0E} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: FlashTEnhancer Ext - {D7E588AB-A5D9-4422-B313-22A3470F9700} - c:\Program Files\Ftk\ftk.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSN Manager] C:\WINDOWS\system32\tsmgr.exe
O4 - HKLM\..\Run: [tr] C:\documents and settings\pat\local settings\temp\tr.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [3TFECJW2RNH4YZ] C:\WINDOWS\System32\Ovbl73H.exe
O4 - HKLM\..\Run: [S1vw] C:\documents and settings\pat\local settings\temp\S1vw.exe
O4 - HKLM\..\Run: [e3943625ed43] C:\WINDOWS\System32\ntlanman.exe
O4 - HKLM\..\Run: [Ljbmrl] C:\Program Files\Ekgmn\Dqic.exe
O4 - HKLM\..\Run: [tvs_b] C:\program files\tvs\tvs_b.exe
O4 - HKLM\..\Run: [3224bd9542a2] C:\WINDOWS\System32\umpnpmgr.exe
O4 - HKLM\..\Run: [cxin] C:\DOCUME~1\Pat\LOCALS~1\Temp\~MySetup.exe
O4 - HKLM\..\Run: [vidctrl] C:\WINDOWS\System32\vidctrl\vidctrl.exe
O4 - HKLM\..\Run: [2TDYN#33SYHFJS] C:\WINDOWS\system32\Cjp9g.exe
O4 - HKLM\..\Run: [FtkCPY] "C:\Program Files\Common Files\Java\ftkcpy.exe"
O4 - HKLM\..\Run: [iiiwmf] c:\windows\system32\vjbrjnl.exe r
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {5C7F15E1-F31A-44FD-AA1A-2EC63AAFFD3A} -
http://www.atelys.com/src/Speedup.ocxO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1119758350258O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.c...utocomplete.cabO23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: AutoComplete Service (Autocomplete) - Internet Washer - C:\PROGRA~1\SYSTEM~1\autocomp.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:22:44 PM, 7/12/2005
+ Report-Checksum: 6D377FB2
+ Scan result:
HKLM\SOFTWARE\Classes\UnawareObj.UnawareObj -> Spyware.FlashTrack : Cleaned with backup
HKLM\SOFTWARE\Classes\UnawareObj.UnawareObj\CurVer -> Spyware.FlashTrack : Cleaned with backup
C:\Program Files\spsr\etts.exe -> Spyware.PurityScan : Cleaned with backup
C:\Documents and Settings\Pat\Local Settings\Temp\1D.tmp\thnall1ac.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Pat\Cookies\pat@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Pat\Cookies\pat@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153838.exe -> Spyware.Delfin : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153839.exe -> Worm.Klez.H : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153840.EXE -> Worm.Klez.H : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153841.EXE -> Worm.Klez.H : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153842.EXE -> Worm.Klez.H : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153843.EXE -> Worm.Klez.H : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153844.exe -> Trojan.Small.cy : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153845.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153846.exe -> TrojanDownloader.Small.adq : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153847.exe -> TrojanDropper.Small.kz : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153848.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153849.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153850.dll -> TrojanDownloader.Qoologic.a : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153851.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153852.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153853.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153854.exe -> Spyware.F1Organizer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153855.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153856.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153857.exe -> Spyware.IEDriver : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153858.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153859.exe -> TrojanDownloader.Agent.ed : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153860.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153861.exe -> Spyware.UrlSpy : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153862.exe -> Spyware.UrlSpy : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153863.exe -> Spyware.DelphinMediaViewer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153864.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153865.exe -> TrojanDownloader.VB.em : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153866.exe -> Spyware.AproposMedia : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153867.exe -> Spyware.BlazeFind : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153868.exe -> Spyware.F1Organizer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153869.exe -> Spyware.F1Organizer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153870.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153871.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153872.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153873.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153878.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153883.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153888.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153945.DLL -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153946.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153952.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153953.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153961.dll -> Spyware.FlashEnhancer : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP488\A0153964.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP477\A0145135.exe -> TrojanDownloader.OneClickSearch.k : Cleaned with backup
C:\System Volume Information\_restore{60AFB83F-2851-48CA-A836-8A05EBD5A4F2}\RP477\A0145472.exe -> TrojanDownloader.Apropo.ac : Cleaned with backup
::Report End
___________________________________________________________________
Incident Status Location
Virus:Trj/Downloader.IU Disinfected Operating system
Adware:Adware/eZula No disinfected C:\WINDOWS\system32\sysfile.dll
Adware:Adware/MyWay No disinfected Windows Registry
Adware:Adware/nCase No disinfected C:\WINDOWS\system32\FLEOK
Adware:Adware/FlashTrack No disinfected Windows Registry
Adware:Adware/PortalScan No disinfected C:\Program Files\Common Files\slmss
Adware:Adware/CWS No disinfected Windows Registry
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\bsx32
Adware:Adware/WinTools No disinfected Windows Registry
Adware:Adware/Sqwire No disinfected C:\WINDOWS\system32\tsuninst.exe
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Pat\Application Data\tvm*.dll
Adware:Adware/DelFinMedia No disinfected Windows Registry
Adware:Adware/SideSearch No disinfected C:\Documents and Settings\Pat\Application Data\Lycos
Adware:Adware/IEDriver No disinfected C:\WINDOWS\system32\Searchx.htm
Adware:Adware/IPInsight No disinfected C:\WINDOWS\alchem.???
Adware:Adware/SideFind No disinfected Windows Registry
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhdom??.bin
Adware:Adware/IEPlugin No disinfected Windows Registry
Spyware:Spyware/RXToolbar No disinfected C:\WINDOWS\system32\RxBarSetup.dll
Adware:Adware/BroadcastPC No disinfected C:\Program Files\Common Files\Java\tvs_inst.exe
Adware:Adware/BroadcastPC No disinfected C:\Program Files\Common Files\Java\tvs_re_inst.exe
Virus:W32/Klez.I Disinfected C:\Program Files\Plus!\Themeexe.W98
Spyware:Spyware/Omi No disinfected C:\WINDOWS\system32\mshpeb.dll
Adware:Adware/IEDriver No disinfected C:\WINDOWS\system32\Searchx.htm
Spyware:Spyware/Omi No disinfected C:\WINDOWS\system32\mscif.exe
Adware:Adware/IEDriver No disinfected C:\WINDOWS\system32\cabinet7.exe
Spyware:Spyware/Omi No disinfected C:\WINDOWS\system32\msnapl.dll
Spyware:Spyware/RXToolbar No disinfected C:\WINDOWS\system32\RxBarSetup.dll
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\jlkfeb.dll
Adware:Adware/ValueAd No disinfected C:\WINDOWS\system32\bpdf.exe
Adware:Adware/eZula No disinfected C:\WINDOWS\system32\sysfile.dll
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\system32\book.dll
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\system32\book2.dll
Adware:Adware/PortalScan No disinfected C:\WINDOWS\system32\winupdt.bin
Adware:Adware/Sqwire No disinfected C:\WINDOWS\system32\tsuninst.exe
Adware:Adware/PurityScan No disinfected C:\WINDOWS\system32\Shex.exe
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\system32\msfaol.dll
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\system32\msiaih.dll
Virus:Trj/Imk.A Disinfected C:\WINDOWS\system32\msnimk.gif
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\system32\mseggo.gif
Spyware:Spyware/ClientMan No disinfected C:\WINDOWS\system32\msglji.gif
Spyware:Spyware/Omi No disinfected C:\WINDOWS\system32\msfdje.gif
Virus:Trj/Siboco.A Disinfected C:\WINDOWS\system32\second.exe
Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\alchem.inf
Adware:Adware/IPInsight No disinfected C:\WINDOWS\alchem.ini
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhdom1.bin
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dhdomp1.bin
Adware:Adware/DealHelper No disinfected C:\WINDOWS\dsearch1.bin
Spyware:Spyware/ShopNav No disinfected C:\WINDOWS\unist2.exe
Virus:Trj/Subsearch.G Disinfected C:\Documents and Settings\All Users\Application Data\IEService\v28.exe
Spyware:Spyware/TVMedia No disinfected C:\Documents and Settings\Pat\Application Data\tvmknwrd.dll