Hi Kool, Ok i have done everything you have said,
Heres the new hijack this log
Logfile of HijackThis v1.99.1
Scan saved at 21:10:16, on 24/07/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\system32\NOTEPAD.EXE
D:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://www.bitdefend...can8/oscan8.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{E4A8F223-6868-46CA-AFF9-3962450528F4}: NameServer = 194.72.0.114 194.74.65.69
O18 - Filter hijack: application/octet-stream - (no CLSID) - (no file)
O18 - Filter hijack: application/x-complus - (no CLSID) - (no file)
O18 - Filter hijack: application/x-msdownload - (no CLSID) - (no file)
O18 - Filter hijack: Class Install Handler - (no CLSID) - (no file)
O18 - Filter hijack: deflate - (no CLSID) - (no file)
O18 - Filter hijack: gzip - (no CLSID) - (no file)
O18 - Filter hijack: lzdhtml - (no CLSID) - (no file)
O18 - Filter hijack: text/webviewhtml - (no CLSID) - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - McAfee, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: McAfee SpamKiller Server (MskService) - Networks Associates Technology. Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
Just so you know i fixed the 018 Values and it seems there back again?
***********SpSeHjfix LOG*************************************
(7/19/05 23:58:25) SPSeHjFix started v1.1.2
(7/19/05 23:58:25) OS: WinXP Service Pack 2 (5.1.2600)
(7/19/05 23:58:25) Language: english
(7/19/05 23:58:25) Win-Path: C:\WINDOWS
(7/19/05 23:58:25) System-Path: C:\WINDOWS\system32
(7/19/05 23:58:25) Temp-Path: C:\DOCUME~1\LOUISA~1\LOCALS~1\Temp\
(7/19/05 23:58:28) Disinfection started
(7/19/05 23:58:28) Bad-Dll(IEP): c:\windows\khhjq.dll
(7/19/05 23:58:28) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:58:28) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:58:28) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page:
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\khhjq.dll/sp.html#55135
(7/19/05 23:58:28) Stealth-String not found
(7/19/05 23:58:28) No locked Files to delete. End without Reboot
(7/19/05 23:58:40) Disinfection started
(7/19/05 23:58:40) Bad-Dll(IEP): c:\windows\khhjq.dll
(7/19/05 23:58:40) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:58:40) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:58:40) Bad IE-pages: (none)
(7/19/05 23:58:40) Stealth-String not found
(7/19/05 23:58:40) No locked Files to delete. End without Reboot
(7/19/05 23:59:20) Disinfection started
(7/19/05 23:59:20) Bad-Dll(IEP): c:\windows\khhjq.dll
(7/19/05 23:59:20) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:20) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:20) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_URL: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\khhjq.dll/sp.html#55135
(7/19/05 23:59:20) Stealth-String not found
(7/19/05 23:59:20) No locked Files to delete. End without Reboot
(7/19/05 23:59:48) SPSeHjFix started v1.1.2
(7/19/05 23:59:48) OS: WinXP Service Pack 2 (5.1.2600)
(7/19/05 23:59:48) Language: english
(7/19/05 23:59:48) Win-Path: C:\WINDOWS
(7/19/05 23:59:48) System-Path: C:\WINDOWS\system32
(7/19/05 23:59:48) Temp-Path: C:\DOCUME~1\LOUISA~1\LOCALS~1\Temp\
(7/19/05 23:59:49) Disinfection started
(7/19/05 23:59:49) Bad-Dll(IEP): c:\windows\khhjq.dll
(7/19/05 23:59:49) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:49) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:49) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: res://c:\windows\khhjq.dll/sp.html#55135
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Default_Page_
(7/19/05 23:59:56) SPSeHjFix started v1.1.2
(7/19/05 23:59:56) OS: WinXP Service Pack 2 (5.1.2600)
(7/19/05 23:59:56) Language: english
(7/19/05 23:59:56) Win-Path: C:\WINDOWS
(7/19/05 23:59:56) System-Path: C:\WINDOWS\system32
(7/19/05 23:59:56) Temp-Path: C:\DOCUME~1\LOUISA~1\LOCALS~1\Temp\
(7/19/05 23:59:57) Disinfection started
(7/19/05 23:59:57) Bad-Dll(IEP): (not found)
(7/19/05 23:59:57) Bad-Dll(IEP) in BHO: (not found)
(7/19/05 23:59:57) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:57) UBF: 7 - UBB: 8 - UBR: 45
(7/19/05 23:59:57) Bad IE-pages: (none)
(7/19/05 23:59:57) Stealth-String not found
(7/19/05 23:59:57) Not infected->END
**********************EWIDO LOG ***************************
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 20:01:04, 24/07/2005
+ Report-Checksum: 725E112C
+ Scan result:
C:\Documents and Settings\Louis Amore\Cookies\louis amore@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Louis Amore\Cookies\louis amore@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Louis Amore\Cookies\louis amore@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\WINDOWS\_ISNU.INI:inwnc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iodnz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iseiw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iseky -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:itzma -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iugzs -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iwekg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iyfph -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:iyzlg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:izdbn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jayyc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jchrc -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jcpwr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jhdim -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jhmri -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jhrba -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jixhq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jiyig -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jlpol -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jmduo -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jmkdf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jqgul -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jqgulm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jqtgs -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jrjsf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jufwm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jvrldn -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jwiuq -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jwncr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jwugp -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:jzjci -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kazge -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kdykv -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kfmoz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kgqmg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kguxw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:khewo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:klfzk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:koqyo -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kphyx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kqvwu -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kqxju -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:krfhd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:krzfha -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kuatr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kvdxt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kvgzw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kwffh -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kwwct -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kxfxk -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kzlkn -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:kzxkb -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:laake -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lbhbue -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:ldmun -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:ldzcm -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lejtg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lewaf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lhzok -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:ligrn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:ljcce -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lmxin -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lmypq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lnbfi -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lnuoow -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lpxlx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lqieg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:ltedz -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:luhxf -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lvdut -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lvgkn -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lvrja -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lwkas -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lygiy -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:lzvrr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mbiqa -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mbisd -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mepjx -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mhdke -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mhsti -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mhvod -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mkxml -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mlqagc -> Trojan.Agent.bi : Cleaned with backup
C:\WINDOWS\_ISNU.INI:moxkc -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mqaao -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mqifm -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mrhdt -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:msrrxg -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mswhw -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINDOWS\_ISNU.INI:murlw -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\WINDOWS\_ISNU.INI:mvllge -> TrojanDownloader.Agent.bq : Cleaned with backup
::Report End
I could not run Panda Scan as Explorer wont open the pop up window for the scan my explorer only works on the Bitdefender website so i Ran it on a FULL SCAN, 4HRS, i CLEANED 1 VIRUS NO LOG PRINT OUT OF IT.
As soon Bitdefender finished the scan Mcafee said C:/System Volume information\_restore {EB5COCA7-E162-4B3E-... was infected by the Genetic Downloader.ab trojan and has been deleted to complete the clean process.
I have started running Ewido again, Macfee is finding new files bieng infected everysecond now,,, /CRY!
[bleep] this is a tough cookie!!!!!!!
I have done everything u said very carefully, :
Edited by Carerra, 24 July 2005 - 02:24 PM.