Sam,
Thanks for all of your help so far. I think I've completed everything as directed.
First, a couple of notes, don't know whether they are important or not.
When I reboot in safe mode, I am logging in under my user name, not as administrator. I am the only user on the computer, so I hope this is correct.
I found none of the files to delete (although there was a cfgmgr52.ini, which i did not delete, but not a .dll), but i did delete the \Cas directory.
Okay, first the Panda results:
Incident Status Location
Adware:adware/apropos No disinfected C:\PROGRAM FILES\Aprps
Adware:adware/elitebar No disinfected C:\DOCUMENTS AND SETTINGS\BRIAN DIETRICH\FAVORITES\Casino & Carrers
Spyware:spyware/surfsidekick No disinfected HKEY_LOCAL_MACHINE\SOFTWARE\SURFSIDEKICK3
Adware:adware/bigtrafficnet No disinfected HKEY_CLASSES_ROOT\Interface\{FA6FA7A5-2C49-4567-BA74-6DD1C36099EE}
Adware:adware/brilliantdigitalNo disinfected HKEY_CLASSES_ROOT\Interface\{48E59292-9880-11CF-9754-00AA00C00908}
Adware:Adware/Apropos No disinfected C:\Program Files\Aprps\ProxyStub.dll
Adware:Adware/ConsumerAlertSystemNo disinfected C:\Program Files\CasStub\casstub.exe
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D2E.tmp\AdDestroyer.exe
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D2F.tmp
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D30.tmp
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D31.tmp
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D32.tmp
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D34.tmp
Adware:Adware/AdDestroyer No disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D35.tmp
Possible Virus. No disinfected C:\WINDOWS\AuroraHandler.dll
Adware:Adware/ConsumerAlertSystemNo disinfected C:\WINDOWS\system32\dist001.exe
Adware:Adware/BigTrafficNet No disinfected C:\WINDOWS\system32\nsv3D29.dll
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\redit.cpl
Virus:Trj/Downloader.BJG Disinfected C:\WINDOWS\system32\SSK3_B5 Seedcorn 4.exe
Adware:Adware/AdBehavior No disinfected C:\WINDOWS\system32\supdate.dll
Virus:Trj/Downloader.BJG Disinfected C:\WINDOWS\system32\uci.exe
Adware:Adware/BookedSpace No disinfected C:\WINDOWS\ycbbuirz.exe
And now the bit defender. (note: it never gave me any kind of list of files that could not be removed, so i'm not sure if you need this or not.)
BitDefender Online Scanner
Scan report generated at: Mon, Jul 18, 2005 - 07:01:38
Scan path: C:\;D:\;
Statistics
Time
00:35:51
Files
127328
Folders
3506
Boot Sectors
2
Archives
950
Packed Files
21016
Results
Identified Viruses
14
Infected Files
56
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
69
Engines Info
Virus Definitions
196227
Engine build
AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)
Scan plugins
13
Archive plugins
39
Unpack plugins
4
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\Program Files\CasStub\casstub.exe
Infected with: Trojan.Downloader.Agent.QG
C:\Program Files\CasStub\casstub.exe
Disinfection failed
C:\Program Files\CasStub\casstub.exe
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\0CD61DEB.exe=>(Quarantine-2)
Infected with: Trojan.Dloader.OS
C:\Program Files\Norton AntiVirus\Quarantine\0CD61DEB.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\0CD61DEB.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\1F1E23CD.exe=>(Quarantine-2)
Detected with: Adware.POP.dl
C:\Program Files\Norton AntiVirus\Quarantine\1F1E23CD.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\1F1E23CD.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\35AC392C.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\35AC392C.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\35AC392C.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\35AF6328.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Delf.GO
C:\Program Files\Norton AntiVirus\Quarantine\35AF6328.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\35AF6328.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\35B30D25.exe=>(Quarantine-2)
Infected with: Trojan.Downloader.Delf.GO
C:\Program Files\Norton AntiVirus\Quarantine\35B30D25.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\35B30D25.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\39826FF1.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\39826FF1.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\39826FF1.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\45122BF0.exe=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\45122BF0.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\45122BF0.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\575A5893.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\575A5893.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\575A5893.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5E8274A1.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\5E8274A1.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\5E8274A1.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\5EE01742.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\5EE01742.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\5EE01742.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\60D275AF.exe=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\60D275AF.exe=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\60D275AF.exe=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\60D51FAC.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\60D51FAC.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\60D51FAC.sys=>(Quarantine-2)
Deleted
C:\Program Files\Norton AntiVirus\Quarantine\60D849A8.sys=>(Quarantine-2)
Infected with: Trojan.Kolweb.A
C:\Program Files\Norton AntiVirus\Quarantine\60D849A8.sys=>(Quarantine-2)
Disinfection failed
C:\Program Files\Norton AntiVirus\Quarantine\60D849A8.sys=>(Quarantine-2)
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019472.exe
Infected with: Trojan.Downloader.Delf.GO
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019472.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019472.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019481.exe
Infected with: Trojan.Downloader.Delf.GO
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019481.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP141\A0019481.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019498.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019498.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019498.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019499.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019499.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019499.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019501.exe
Infected with: Trojan.Downloader.Delf.GO
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019501.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019501.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019502.exe
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019502.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019502.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019523.exe
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019523.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019523.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019525.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019525.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019525.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019526.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019526.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP142\A0019526.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019532.exe
Infected with: Trojan.Dropper.Delf.EV
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019532.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019532.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019578.EXE
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019578.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP143\A0019578.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019616.exe
Infected with: Trojan.Dropper.Delf.EV
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019616.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019616.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019617.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019617.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019617.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019619.exe
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019619.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019619.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019620.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019620.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019620.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019621.EXE
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019621.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019621.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019622.exe
Infected with: Trojan.Dropper.Delf.EV
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019622.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019622.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019623.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019623.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019623.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019624.sys
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019624.sys
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019624.sys
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019626.exe
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019626.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019626.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019628.EXE
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019628.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019628.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019641.EXE
Infected with: Trojan.Kolweb.A
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019641.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP145\A0019641.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029607.exe
Infected with: Trojan.Downloader.Small.ABD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029607.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029607.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029608.exe
Infected with: Trojan.Downloader.Small.ABD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029608.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP210\A0029608.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029768.exe
Infected with: Trojan.Downloader.Small.ABD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029768.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029768.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029969.exe
Infected with: Trojan.Dropper.Agent.HH
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029969.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029969.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029971.exe
Infected with: Trojan.Startpage.NK
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029971.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029971.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029972.exe
Infected with: Trojan.Dropper.Agent.KD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029972.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029972.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029974.EXE
Infected with: Trojan.Startpage.NK
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029974.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0029974.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030035.exe
Infected with: Trojan.Downloader.Intexp.C
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030035.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030035.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030036.EXE
Infected with: Trojan.Dropper.Agent.HL
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030036.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030036.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030039.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030039.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030040.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP213\A0030040.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030102.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030102.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030103.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030103.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030111.exe
Infected with: Trojan.Agent.AY
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030111.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030135.exe
Infected with: Trojan.Startpage.NK
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030135.exe
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030135.exe
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030221.EXE
Detected with: Adware.POP.dl
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030221.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030221.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030335.EXE
Infected with: Trojan.Downloader.Small.ABD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030335.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030335.EXE
Deleted
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030337.EXE
Infected with: Trojan.Downloader.Small.ABD
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030337.EXE
Disinfection failed
C:\System Volume Information\_restore{BCB42CE0-127D-4B0B-8EE7-06F955E05E54}\RP214\A0030337.EXE
Deleted
C:\WINDOWS\system32\dist001.exe
Infected with: Trojan.Downloader.Agent.QG
C:\WINDOWS\system32\dist001.exe
Disinfection failed
C:\WINDOWS\system32\dist001.exe
Deleted
C:\WINDOWS\system32\supdate.dll
Infected with: Trojan.Downloader.Qoologic.P
C:\WINDOWS\system32\supdate.dll
Deleted
And now the new hjt log.
Logfile of HijackThis v1.99.1
Scan saved at 7:28:05 AM, on 7/18/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\MMDiag.exe
C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Brian Dietrich\Desktop\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://us8l.hpwis.com/O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: Registration Brothers In Arms.LNK = D:\Support\Register\RegistrationReminder.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) -
http://housecall60.t...all/xscan60.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....467&clcid=0x409O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://appldnld.m7z....iTunesSetup.exeO16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1121129824406O16 - DPF: {85D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin class) -
http://secure2.comne...login-devel.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.ao.../ampx_en_dl.cabO23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Thanks.