Hi Kat and Bobbi!
I ran the ewido scan and ALL those dang trojan downloaders showed up on the scan!!!!
I removed them with ewido in safe mode. How did they get in there? Are they in quarintine? Are they gone permanently now?
I tell ya all the hassle with that **** sure takes the enjoyment out of using the computer anymore. And my son got routed to a site today that loaded Hacktool.Rootkit on his computer....boy is it messed-up.
Here is the Ewido and HJT logs:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 12:09:49 AM, 10/11/2005
+ Report-Checksum: E0E27054
+ Scan result:
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:jujby -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:jvapun -> Spyware.SearchPage : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:jwnkl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kdegj -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kdttb -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kdupr -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kemse -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kfcgn -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kgqvz -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kgxfl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:khlwgu -> Trojan.Agent.bi : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kjtbg -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kkdzp -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kotjt -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kplgn -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:krjtz -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:krmvq -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ktqsm -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kxasm -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kymwi -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:kzfsl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:lcdigi -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:lszge -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:lvxjj -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:maoia -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mfcps -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mkbsb -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mlkdi -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mmwrb -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mxwyng -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ndtggb -> Backdoor.Netag : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:niaqh -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:nioaz -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:nlmxv -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ntxfr -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:nxaseq -> Trojan.Agent.bi : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:nzppe -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:oapse -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:obtms -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ocxch -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:odyfd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ofhoo -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ohnad -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:oibwe -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ojuww -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:okoqd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:ookms -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:oprhl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:orbbb -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:orhel -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:osnjl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:otrbh -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:oapse -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:obtms -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ocxch -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:odyfd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ofhoo -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ohnad -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:oibwe -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ojuww -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:okoqd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ookms -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:oprhl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:orhel -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:osnjl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:otrbh -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:oujnr -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:oylnb -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:paavi -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:paeor -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pdvei -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pgiqf -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:phznv -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pilsz -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pkygd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:plqtt -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pouxw -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ppigo -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:prjfy -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:ptwsm -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pwgwrt -> Backdoor.Netag : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pwirv -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pwodm -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pyaeg -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pyfnt -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:pzakz -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qahyt -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qajay -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qbqkd -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qbybd -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qcghx -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qczil -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qdfam -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qedva -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qjmen -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qjqsz -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qldtl -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qmqpz -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qoilt -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qplnt -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qtwik -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:qwoqj -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:raagf -> TrojanDownloader.Agent.bq : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:rbfds -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:nzppe -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:oapse -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:obtms -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ocxch -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:odyfd -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ofhoo -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ohnad -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:oibwe -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ojuww -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:okoqd -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ookms -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:osnjl -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:otrbh -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:oujnr -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:oylnb -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:paavi -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:paeor -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pdvei -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:pgiqf -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:phznv -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:pilsz -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:plqtt -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:ppigo -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:prjfy -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:ptwsm -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pwgwrt -> Backdoor.Netag : Ignored
C:\WINNT\_ISREG32.DLL:pwirv -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pwodm -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pyaeg -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pyfnt -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:pzakz -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qahyt -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qajay -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qbqkd -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qbybd -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qcghx -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qczil -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qdfam -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qedva -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qjmen -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qjqsz -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qldtl -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qmqpz -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qoilt -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:qplnt -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qtwik -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:qwoqj -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:raagf -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:rbfds -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:rbspq -> TrojanDownloader.Agent.bc : Ignored
C:\WINNT\_ISREG32.DLL:rdccl -> TrojanDownloader.Agent.bq : Ignored
C:\WINNT\_ISREG32.DLL:rfbee -> TrojanDownloader.Agent.bc : Ignored
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:lcuqq -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:mkygr -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:nisbv -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:njhcr -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012927.DLL:npjum -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:nzppe -> TrojanDownloader.Agent.bq : Cleaned with backup
C:\System Volume Information\_restore{DA924DAC-A2CA-444D-A346-208E6B4D0203}\RP23\A0012938.DLL:orbbb -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\_ISREG32.DLL:pkygd -> TrojanDownloader.Agent.bc : Cleaned with backup
C:\WINNT\_ISREG32.DLL:pouxw -> TrojanDownloader.Agent.bc : Cleaned with backup
::Report End
HERE IS THE FIRST SCAN IN SAFE MODE>>>>I removed the trojans but they came back when I did the scan while running in normal mode, WHY?
HJT LOG FILE:
Logfile of HijackThis v1.99.1
Scan saved at 12:16:19 AM, on 10/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\csrss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\wscntfy.exe
C:\WINNT\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.gatewaybiz.com/O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} -
C:\PROGRA~1\SPYWAR~2\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} -
C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy
Sweeper\SpySweeper.exe" /startintray
O4 - Global Startup: Grouper.lnk = C:\WINNT\adduc32.exe
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -
C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} -
C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96}
- C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger -
{E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} -
C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144
- {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: JT's Blocks -
http://download.game...ts/y/blt1_x.cabO16 - DPF: Tornado 21 -
http://download.game...s/y/t21t0_x.cabO16 - DPF: Video Poker -
http://download.game...ts/y/vpt0_x.cabO16 - DPF: Yahoo! Bingo -
http://download.game...nts/y/xt0_x.cabO16 - DPF: Yahoo! Blackjack -
http://download.game...nts/y/jt0_x.cabO16 - DPF: Yahoo! Canasta -
http://download.game...nts/y/yt1_x.cabO16 - DPF: Yahoo! Chat -
http://us.chat1.yimg...t/c381/chat.cabO16 - DPF: Yahoo! Dice -
http://download.game...ts/y/dct2_x.cabO16 - DPF: Yahoo! Dots -
http://download.game...ts/y/dtt1_x.cabO16 - DPF: Yahoo! GoStop -
http://download.game...ts/y/gst1_x.cabO16 - DPF: Yahoo! Hearts -
http://download.game...nts/y/ht1_x.cabO16 - DPF: Yahoo! Klondike Solitaire -
http://yog55.games.s...og/y/ks12_x.cabO16 - DPF: Yahoo! MahJong -
http://download.game...nts/y/ot0_x.cabO16 - DPF: Yahoo! MahJong Solitaire -
http://download.game...s/y/mjst4_x.cabO16 - DPF: Yahoo! Poker -
http://download.game...nts/y/pt3_x.cabO16 - DPF: Yahoo! Pool 2 -
http://download.game...ts/y/pote_x.cabO16 - DPF: Yahoo! Pyramids -
http://download.game...ts/y/pyt1_x.cabO16 - DPF: Yahoo! Spades -
http://download.game...nts/y/st2_x.cabO16 - DPF: Yahoo! Spelldown -
http://download.game...ts/y/sdt1_x.cabO16 - DPF: Yahoo! Towers 2.0 -
http://download.game...ts/y/ywt0_x.cabO16 - DPF: Yahoo! Word Racer -
http://download.game...nts/y/wt1_x.cabO16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} -
http://www.photopara...ll/phpsetup.cabO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage
Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -
https://www-secure.s...rl/LSSupCtl.cabO16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...ple.com/drakken/us/win/QuickTimeInstaller.exe
O16 - DPF: {58FC4C77-71C2-4972-A8CD-78691AD85158} (BJA Control) -
http://www.worldwinn...ck/bjattack.cabO16 - DPF: {62969CF2-0F7A-433B-A221-FD8818C06C2F} (Blockwerx Control) -
http://mirror.worldw...x/blockwerx.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros.../client/wuweb_site.cab?1122861135035
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility
Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {6BB594E2-6E4D-4CC9-98B0-931C323F9165} (DepHlp Control) -
http://mirror.worldw...ared/dephlp.cabO16 - DPF: {6F6DBC29-7A0C-4AC0-A42D-10EC70678526} (Word Cubes Control) -
http://www.worldwinn...be/wordcube.cabO16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) -
hcp://system/RunExeActiveX.CAB
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
https://www.worldwin...ed/wwlaunch.cabO16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) -
http://212.150.183.2...sCamControl.ocxO16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1}
(StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) -
http://zone.msn.com/...me/ZAxRcMgr.cabO16 - DPF: {AC2881FD-5760-46DB-83AE-20A5C6432A7E} (SwapIt Control) -
http://www.worldwinn...apit/swapit.cabO16 - DPF: {B06CE1BC-5D9D-4676-BD28-1752DBF394E0} (Hangman Control) -
http://mirror.worldw...man/hangman.cabO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.c...utocomplete.cabO16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tile City Control) -
http://www.worldwinn...ty/tilecity.cabO16 - DPF: {C93C1C34-CEA9-49B1-9046-040F59E0E0D8} (Paint Control) -
http://www.worldwinn...paint/paint.cabO16 - DPF: {CA034DCC-A580-4333-B52F-15F98C42E04C} -
http://www.stopzilla...ller/dwnldr.cabO16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.s...rl/SymAData.cabO16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) -
http://ax.phobos.app.../ITDetector.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://download.game...ed2/popcaploader_v6.cab
O16 - DPF: {E70E3E64-2793-4AEF-8CC8-F1606BE563B0} (WWSpades Control) -
http://www.worldwinn...es/wwspades.cabO16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} -
http://download.abac...abasetup144.cabO16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) -
http://www.worldwinn...ool/h2hpool.cabO17 -
HKLM\System\CCS\Services\Tcpip\..\{225E7E60-D36F-4D91-8256-B7677C95778D}:
NameServer = 192.168.1.1
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner -
C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program
Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program
Files\ewido\security suite\ewidoguard.exe
O23 - Service: NICSer_WPC54G - Unknown owner - C:\Program
Files\Linksys\Wireless-G Notebook Adapter\NICServ.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\system32\HPZipm12.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software,
Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe