Good morning!
Is that a folder or a file. I didn't see an extension on it.
updatees.exe is an application
Below you have the list of files I am suspicious about, and below that the results of MWAV. MWAV does say that updatees is infected!!! Now running Ewido again, will post results soon.
THANK YOU!
Libby
++++++++++++
Here is a list of the files that I can't find enough info about on the Web, and I don't like the fact that they've been modified since I got infected (date listed is modified date).
C:\
23990098.$$$ $$$ File 8/12 4:48am
AVPCallback Text 8/11 11:38pm
(these two maybe from running MWAV?)
c:\WINDOWS
win.ini Configuration settings 0KB 8/11 10:16 (last logon)
0 Text 8/11 10:16 (last logon)
TSC.ini Configuration 8/11 9:14am (logged on)
RM-RESULT.dat DAT file 8/11 9:14am (logged on)
TMUPDATE.DLL App extension 8/11 9:01am (logged on)
UNZIP.DLL App extension 8/11 9:01am (logged on)
PATCH Application 8/11 9:01am (logged on)
machine.ver VER File 8/10 10:52pm
VPTNFILE.771 771 File 8/10 1:59pm (computer in standby mode)
lpt$vpn.771 771 File 8/10 1:59pm (computer in standby mode)
Kyor.ini Text 8/8 11:59pm
updatees Application 8/3 4:58pm
++++++++++++
And here are the results from MWAV, line feeds added to make it easier to read. I have already deleted the attached message.zip (never opened).
Object "Quicken Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "iSearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\USWebUncoated.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\AppleRGB.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\ColorMatchRGB.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\EuroscaleCoated.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\EuroscaleUncoated.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\JapanStandard.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\sRGB Color Space Profile.icm". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\USSheetfedCoated.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\USSheetfedUncoated.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\USWebCoatedSWOP.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Recommended\AdobeRGB1998.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\WideGamutRGB.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\NTSC1953.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\PAL_SECAM.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\SMPTE-C.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\CIERGB.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\Photoshop5DefaultCMYK.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Adobe\Acrobat 5.0\TempICCProfiles\Profiles\Non-Recommended\Photoshop4DefaultCMYK.icc". Action Taken: No Action Taken.
Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Adobe\Fonts\Reqrd\Base\AdobeFnt.lst". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{000287CC-0000-0000-C000-000000000046}" refers to invalid object "apprclip.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{29134141-2EED-1069-BF5D-00DD011186B7}" refers to invalid object "LWPEQNN.DLL". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765C5-AE47-11D1-9975-00805F8AC6B3}" refers to invalid object "brpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765C6-AE47-11D1-9975-00805F8AC636}" refers to invalid object "brpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765C7-AE47-11D1-9975-00805F8AC6B3}" refers to invalid object "brpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765C8-AE47-11D1-9975-00805F8AC6B3}" refers to invalid object "edpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765CB-AE47-11D1-9975-00805F8AC63E}" refers to invalid object "mnpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{2FC765CC-AE47-11D1-9975-00805F8AC6B3}" refers to invalid object "mnpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{62845280-4FE2-11D1-8EAC-00805FD26FAA}" refers to invalid object "lipref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{744C3DF0-DFAE-11D1-826B-00805F2AB103}" refers to invalid object "brpref32.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{7730E78F-A89A-11D3-9982-0060B088BBCA}" refers to invalid object "C:\PROGRA~1\AMERIC~1.0\AMP\ampx.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken.
Entry "HKCR\CLSID\{99180163-DA16-101A-935C-444553540000}" refers to invalid object "recncl.dll". Action Taken: No Action Taken.
Entry "HKCR\ActMsg.Session" refers to invalid object "{3FA7DEB3-6438-101B-ACC1-00AA00423326}". Action Taken: No Action Taken.
Entry "HKCR\Layout" refers to invalid object "{812AE312-8B8E-11CF-93C8-00AA00C08FDF}". Action Taken: No Action Taken.
Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken.
Entry "HKCR\PRLOTREG.PrlotregCtrl.1" refers to invalid object "{129550A5-75C9-11D3-9F87-00600894B1EE}". Action Taken: No Action Taken.
File C:\WINDOWS\updatees.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP137\A0047419.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP137\A0047432.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047471.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047536.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047540.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048650.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048666.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048680.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048685.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0049213.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051411.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051424.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051441.exe infected by "Backdoor.Win32.Agent.mo" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP144\A0055791.exe infected by "Backdoor.Win32.Rbot.gen" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP144\A0055991.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP149\A0057313.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP150\A0057361.exe infected by "Trojan-Proxy.Win32.Agent.fy" Virus! Action Taken: No Action Taken.
File C:\Users\libby\Eudora\Attach\message.zip infected by "Email-Worm.Win32.Mydoom.m.log" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\updatees.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP137\A0047419.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP137\A0047432.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047471.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047536.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0047540.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048650.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048666.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048680.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0048685.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP138\A0049213.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051411.sys infected by "Rootkit.Win32.Agent.p" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051424.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP140\A0051441.exe infected by "Backdoor.Win32.Agent.mo" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP144\A0055791.exe infected by "Backdoor.Win32.Rbot.gen" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP144\A0055991.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP149\A0057313.exe infected by "Trojan-Proxy.Win32.Ranky.bu" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{C7DDC5E1-A6C6-443B-AE4B-FEEAEF64E4B9}\RP150\A0057361.exe infected by "Trojan-Proxy.Win32.Agent.fy" Virus! Action Taken: No Action Taken.
File C:\Users\libby\Eudora\Attach\message.zip infected by "Email-Worm.Win32.Mydoom.m.log" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\updatees.exe infected by "Trojan-Clicker.Win32.Small.hh" Virus! Action Taken: No Action Taken.