Excal,
Things are looking better. Here are the logs in the order that they were executed.
The following things were noted.
1. HJT was not able to remove
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\syshc.exe (file missing) Should I be concerned about this?
2. under step 12. the file names you noted were present but all in caps and with additional tex (MFCSZ32.EXE-09561AAE.pf). They were recent files. I deleted them. Hope that is not a bad thing.
3. Panda found no viruses but I was unable to get a log. Must have been doing something wrong. At the end of the scan the choose profile dialog box for outlook would come up. I will scan again.
4. I see two new files on the desktop. One is named desktop and has the following contents ([LocalizedFileNames]
Windows Media Player.lnk=@C:\WINDOWS\inf\unregmp2.exe,-4)
The second is named Thumbs (unknown application) Can I delete these?
Thank you,
Joe
ewido security suite - Scan report---------------------------------------------------------
+ Created on: 7:27:53 PM, 7/13/2005
+ Report-Checksum: A96D0F34
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{74339574-CCF2-3651-E5EA-88C8BFBBFB28} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A0B249A8-05AF-32B0-992B-DB1CAFDEB3E4} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AF197E67-53B8-6C01-4733-3E7C25BA3A3B} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F065E398-2ACB-9034-8B2A-28A827FF521F} -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SE -> Spyware.CoolWebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SW -> Spyware.CoolWebSearch : Cleaned with backup
HKU\S-1-5-21-2348792268-1007953774-3110568756-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{74339574-CCF2-3651-E5EA-88C8BFBBFB28} -> Spyware.CoolWebSearch : Cleaned with backup
C:\Program Files\HJT\backups\backup-20050712-204310-214.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\addbm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addff.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addmb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addvr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\addwx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apihs32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiij32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apioh.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apirw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apitw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apiyc32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\apiyc32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apizn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\apphw.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appic.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\appqo.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\apptd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\appym32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\atlir32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\atljp32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\crvc32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3lr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\d3sx.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DEBUGSM.INI:ckoor -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DEBUGSM.INI:edxtu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DEBUGSM.INI:xfeyl -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\DESKTOP.INI:uhpsz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\EPSON Perfection 3170.ini:mkgtw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\EPSON Perfection 3170.ini:ynxeg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\EPSTPLOG.TXT:jxcey -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Film Factory.scr:xljms -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\GMUD32.INI:pjvxr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\GMUD32.INI:uznxu -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\iefy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieia.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ieji32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipku32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipoj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ipuo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ivybi.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\javadt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javamx.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javaxn.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\javayb.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\javazu.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\lrun32.ini:aptio -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\lrun32.ini:sjsxc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcbu32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfccd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfcdm32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\mfcqq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\mfctv.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msiz32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\msnf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\msvy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netbm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netfz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netmg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netnz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netql32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\netwo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntbl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntbtlog.txt:fokav -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntdz.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\nthq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntlm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntls.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ntmi.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\ntrl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ntvi.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:tbcpm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\ODBCINST.INI:yzbjh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\OEWABLog.txt:bccwx -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\orun32.ini:uvmbb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:bwdig -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SchedLgU.Txt:ulnuq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\sdkcm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkgg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sdkxr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SETUPLOG.TXT:wdeic -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\smscfg.ini:bbokzc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\smscfg.ini:wcgzn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\smscfg.ini:wihfc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\sysey32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysgo32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysjv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\sysml.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM.INI:hjkxq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM.INI:xfnvi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\addfj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\addnc.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\addvl.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32\apial32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\apial32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32\apiei32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\apijj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\apimi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\apipv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\appee32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\appen.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\appry.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\atlav.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\atlhd.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\atloj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\atlse32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\atlyd32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32\crag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\crkz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\crpk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\crsd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\crus.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\d3tt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\iecr32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ieyf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\iplv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ipsj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\javacb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\javajs32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\javame.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfccz32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcff.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcfw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcke32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcre32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcsm32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcvn32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mfcws.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\msaj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\msgp32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\msio32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\msjt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mspg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mstl32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\msyr.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\mszg32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\netgt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\netoq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\netvm.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntby32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntdq32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntfd32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntnd.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntrc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\nttj.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntvb.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\ntvt.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\oyiok.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkag.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkjo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkpk.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkxv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sdkzz32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32\sysbo.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sysde32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\SYSTEM32\sysev32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\syshk32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sysng.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\systg32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\sysvy.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\syswc.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winff32.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\SYSTEM32\winnw32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winod32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winol.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winsi32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winvj32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winvv32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\winxb32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\SYSTEM32\xcskc.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\sysxt.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\tdwsp.dll -> Spyware.SearchPage : Cleaned with backup
C:\WINDOWS\Topo4.ini:buceh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\Topo4.ini:wqkhm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\VB.INI:igqge -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\VB.INI:uuvjj -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WIN.INI:uidgb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\WIN.INI:vkvsa -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winac.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winjr.dll -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\winmg.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\wintl.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winve32.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winvf.exe -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\winxr.exe -> Trojan.Agent.bi : Cleaned with backup
AboutBuster 5.0 reference file 30Scan started on [7/13/2005] at [8:09:17 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:nskvra
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:qwrzdw
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:spjblx
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:vfcikl
------------------------------------------------
No Files Found!
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 8:09:30 PM
AboutBuster 5.0 reference file 30
Scan started on [7/13/2005] at [8:07:45 PM]
------------------------------------------------
Removed Stream! C:\WINDOWS\KB837001.log:wyfsqy
Removed Stream! C:\WINDOWS\KB840315.log:oyyxki
Removed Stream! C:\WINDOWS\KB842773.log:hzqlnt
Removed Stream! C:\WINDOWS\KB887742.log:syylqh
Removed Stream! C:\WINDOWS\KB890047.log:lzjqkr
Removed Stream! C:\WINDOWS\MedCtrOC.log:ugzeyx
Removed Stream! C:\WINDOWS\MSMQINST.LOG:ehsksz
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:gsdjul
Removed Stream! C:\WINDOWS\{5C29D06B-AA9F-4554-BD34-3C3AC013F59E}.dat:ngvoev
------------------------------------------------
Removed File! : C:\Windows\wvuxs.dat
------------------------------------------------
Scan was COMPLETED SUCCESSFULLY at 8:07:59 PM
(7/13/05 8:10:55 PM) SPSeHjFix started v1.1.2(7/13/05 8:10:55 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/13/05 8:10:55 PM) Language: english
(7/13/05 8:10:55 PM) Win-Path: C:\WINDOWS
(7/13/05 8:10:55 PM) System-Path: C:\WINDOWS\system32
(7/13/05 8:10:55 PM) Temp-Path: C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\
(7/13/05 8:11:49 PM) SPSeHjFix started v1.1.2
(7/13/05 8:11:49 PM) OS: WinXP Service Pack 2 (5.1.2600)
(7/13/05 8:11:49 PM) Language: english
(7/13/05 8:11:49 PM) Win-Path: C:\WINDOWS
(7/13/05 8:11:49 PM) System-Path: C:\WINDOWS\system32
(7/13/05 8:11:49 PM) Temp-Path: C:\DOCUME~1\JOSEPH~1\LOCALS~1\Temp\
(7/13/05 8:11:55 PM) Disinfection started
(7/13/05 8:11:55 PM) Bad-Dll(IEP): (not found)
(7/13/05 8:11:55 PM) Bad-Dll(IEP) in BHO: (not found)
(7/13/05 8:11:55 PM) UBF: 4 - UBB: 2 - UBR: 10
(7/13/05 8:11:55 PM) UBF: 4 - UBB: 2 - UBR: 10
(7/13/05 8:11:55 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL:
(7/13/05 8:11:55 PM) Stealth-String not found
(7/13/05 8:11:55 PM) Not infected->END
Logfile of HijackThis v1.99.1Scan saved at 9:39:20 PM, on 7/13/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Intel\ASF Agent\ASFAgent.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Fixsoftware\security suite\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://smbusiness.dellnet.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.reuters.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Class - {2E2D4B26-4CD2-E13B-EE1F-3BB2852CDEAC} - C:\WINDOWS\system32\sdkpk.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [d3sx.exe] C:\WINDOWS\d3sx.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\E_SRCV02.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chat -
http://us.chat1.yimg...t/c381/chat.cabO16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD 2002\AcDcToday.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) -
http://community.web...otoUploader.CABO16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD 2002\InstBanr.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD 2002\AcPreview.ocx
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\syshc.exe (file missing)O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - C:\Program Files\Intel\ASF Agent\ASFAgent.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\Fixsoftware\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe