Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Search-h, WinFix, and Loads of Popups


  • Please log in to reply

#16
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Thanks for hanging in there.


-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, September 06, 2005 07:29:46
Operating System: Microsoft Windows 2000 Professional, Service Pack 4 (Build 2195)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 4/09/2005
Kaspersky Anti-Virus database records: 138843
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\

Scan Statistics:
Total number of scanned objects: 81896
Number of viruses found: 10
Number of infected objects: 151
Number of suspicious objects: 7
Duration of the scan process: 8603 sec

Infected Object Name - Virus Name
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 23:09 from cpurcell@network-intelligence.com:Hi/body.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml/[From sales@everestbroadband.com][Date Tue, 27 Jan 2004 15:35:39 -0600]/UNNAMED/message.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml/[From sales@everestbroadband.com][Date Tue, 27 Jan 2004 15:35:39 -0600]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/27 Jan 2004 21:38 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 22:38 from System Administrator:Undeliverable: Hi/28 Jan 2004 22:38 to dave@accordionnet.com:Hi/file.zip/file.txt .exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 22:38 from System Administrator:Undeliverable: Hi/28 Jan 2004 22:38 to dave@accordionnet.com:Hi/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 23:23 from postmaster@tridentmicro.com:Delivery Stat/28 Jan 2004 23:23 from bdorsey@everestbroadband.com:Test/file.zip/file.txt .exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/28 Jan 2004 23:23 from postmaster@tridentmicro.com:Delivery Stat/28 Jan 2004 23:23 from bdorsey@everestbroadband.com:Test/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 11:55 from Postmaster@uxtpaprx1.pwcglobal.com:DELIVE/29 Jan 2004 11:45 from wdorsey@datalinx.net/document.zip/document.doc .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 11:55 from Postmaster@uxtpaprx1.pwcglobal.com:DELIVE/29 Jan 2004 11:45 from wdorsey@datalinx.net/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 16:22 from Mail Delivery Subsystem:Returned mail: Us/29 Jan 2004 16:20 from sales@everestbroadband.com:JCRMOM/text.zip/text.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 16:22 from Mail Delivery Subsystem:Returned mail: Us/29 Jan 2004 16:20 from sales@everestbroadband.com:JCRMOM/text.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 22:58 from kcrews@iupui.edu:hello/doc.zip/doc.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 22:58 from kcrews@iupui.edu:hello/doc.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from MAILER-DAEMON@smtp1.everestbroadband.com:.eml/[From bdorsey@everestbroadband.com][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED/readme.zip/readme.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from MAILER-DAEMON@smtp1.everestbroadband.com:.eml/[From bdorsey@everestbroadband.com][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from MAILER-DAEMON@smtp1.everestbroadband.com:.eml/[From bdorsey@everestbroadband.com][Date Thu, 29 Jan 2004 16:32:44 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 21:32 from MAILER-DAEMON@smtp1.everestbroadband.com:.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 20:57 from bulletinsports@yahoo.com:hi/message.zip/message.bat Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/29 Jan 2004 20:57 from bulletinsports@yahoo.com:hi/message.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/30 Jan 2004 19:01 from localg@localgspot.com:atuhlipbige/body.zip/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/30 Jan 2004 19:01 from localg@localgspot.com:atuhlipbige/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:15 from Mail Delivery Service:Delivery Status Not/01 Feb 2004 23:10 to robert@mail2florence.com:Mail Transaction F/readme.zip/readme.exe Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:15 from Mail Delivery Service:Delivery Status Not/01 Feb 2004 23:10 to robert@mail2florence.com:Mail Transaction F/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:05 from Mail Delivery Subsystem:Returned mail: se/01 Feb 2004 23:05 from bdorsey@everestbroadband.com:TEST/document.zip/document.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 23:05 from Mail Delivery Subsystem:Returned mail: se/01 Feb 2004 23:05 from bdorsey@everestbroadband.com:TEST/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/01 Feb 2004 08:51 from postmaster@datamax.com:Delivery Status No/01 Feb 2004 08:50 to ray@datamax.com:hi/file.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from MAILER-DAEMON@www.marketgiantsuccess.com:.eml/[From bdorsey@everestbroadband.com][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED/readme.zip/readme.txt .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from MAILER-DAEMON@www.marketgiantsuccess.com:.eml/[From bdorsey@everestbroadband.com][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from MAILER-DAEMON@www.marketgiantsuccess.com:.eml/[From bdorsey@everestbroadband.com][Date Sat, 31 Jan 2004 01:58:18 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 06:58 from MAILER-DAEMON@www.marketgiantsuccess.com:.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 03:28 from legal@ssb.com.gh:Status/document.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED/body.zip/body.txt .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 30 Jan 2004 20:38:25 -0500]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/31 Jan 2004 01:38 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/03 Feb 2004 06:10 from rosedame@sentoo.sn/doc.cmd Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED/readme.zip/readme.txt .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED/readme.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Tue, 3 Feb 2004 20:41:18 -0800]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 04:45 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/04 Feb 2004 22:50 from TELUS Mail Administrator:Your Message Cou/04 Feb 2004 22:50 from sales@everestbroadband.com:hi/test.pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 02:30 from The Post Office:Delivery reports about yo/05 Feb 2004 01:11 from bdorsey@everestbroadband.com:hello/dclz.zip/dclz.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 02:30 from The Post Office:Delivery reports about yo/05 Feb 2004 01:11 from bdorsey@everestbroadband.com:hello/dclz.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 15:49 from scoulter@gwsae.org:ydy/document.zip/document.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/05 Feb 2004 15:49 from scoulter@gwsae.org:ydy/document.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/06 Feb 2004 15:01 from Mail Delivery Subsystem:Returned mail: se/06 Feb 2004 14:54 from bdorsey@everestbroadband.com/file.zip/file.htm .pif Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/06 Feb 2004 15:01 from Mail Delivery Subsystem:Returned mail: se/06 Feb 2004 14:54 from bdorsey@everestbroadband.com/file.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:19 from postmaster@consumerinfo.com:Delivery Stat/07 Feb 2004 00:18 from bdorsey@everestbroadband.com:Mail Deliver/test.zip/test.doc .scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:19 from postmaster@consumerinfo.com:Delivery Stat/07 Feb 2004 00:18 from bdorsey@everestbroadband.com:Mail Deliver/test.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED/text.zip/text.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED/text.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml/[From bdorsey@everestbroadband.com][Date Fri, 6 Feb 2004 16:13:06 -0800]/UNNAMED Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/07 Feb 2004 00:14 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/08 Feb 2004 04:36 from Mail Administrator:Mail System Error - Re/08 Feb 2004 04:40 from bdorsey@everestbroadband.com:hello/body.zip/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/08 Feb 2004 04:36 from Mail Administrator:Mail System Error - Re/08 Feb 2004 04:40 from bdorsey@everestbroadband.com:hello/body.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 11:31 from andyamoako@yahoo.com:Hello/body.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 08:57 from MMS MX119 Notifier:MMS Notification/09 Feb 2004 07:59 to olivier.haise@usbank.com:hello/doc.zip/doc.scr Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst/Archive Folders/Deleted Items/09 Feb 2004 08:57 from MMS MX119 Notifier:MMS Notification/09 Feb 2004 07:59 to olivier.haise@usbank.com:hello/doc.zip Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\archive.pst Infected: Email-Worm.Win32.Mydoom.a
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/17 Nov 2003 19:27 from Administrator:Undeliverable Message User .rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/23 Nov 2003 12:11 from Postmaster:returned mail: returned to sen.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Deleted Items/22 Nov 2003 12:29 from Inet Mail Delivery System:Error Announcem.rtf Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml/[From <sales@everestbroadband.com>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED/document_9446.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml/[From <sales@everestbroadband.com>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Aug 2003 07:56 from Mail Delivery System:Mail delivery failed.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 15:17 from Randy Kual:RE: failure notice.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/22 Aug 2003 16:21 from Randy Kual:RE: failure notice.eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from maildaemon@puremail.com.eml/[From "" <maildaemon@puremail.com>][Date Sat, 20 Sep 2003 13:50:24 -0400]/html Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from maildaemon@puremail.com.eml/[From "" <maildaemon@puremail.com>][Date Sat, 20 Sep 2003 13:50:24 -0400]/hqiq.exe Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/20 Sep 2003 17:50 from maildaemon@puremail.com.eml Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml/[From "Administrator" <masterbot@aol.com>][Date Fri, 10 Oct 2003 12:19:23 -0200]/html Suspicious: Exploit.HTML.Iframe.FileDownload
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml/[From "Administrator" <masterbot@aol.com>][Date Fri, 10 Oct 2003 12:19:23 -0200]/clpsik.exe Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Inbox/10 Oct 2003 15:23 from Administrator:Returned Message.eml Infected: Email-Worm.Win32.Swen
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <sales@everestbroadband.com>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED/document_9446.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <sales@everestbroadband.com>][Date Wed, 20 Aug 2003 2:57:47 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/20 Aug 2003 13:37 to Randy Kual (E-mail); James Szeliga (E-mail).eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 14:25 to Randy Kual (E-mail); James Szeliga (E-mail).eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED/your_document.pif Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml/[From <sales@everestbroadband.com>][Date Fri, 22 Aug 2003 6:04:49 --0500]/UNNAMED Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst/Personal Folders/Sent Items/22 Aug 2003 15:31 to 'Randy Kual'; 'James Szeliga (E-mail)':RE: .eml Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\mailbox.pst Infected: Email-Worm.Win32.Sobig.f
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:02 from Didi Hadas:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:01 from Didi Hadas:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:05 from Dov Brand:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Tzahi Bahar:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from David Saada:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:09 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from Tzahi Bahar:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:08 from David Saada:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:07 from Ronny Weisman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:07 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Dov Brand:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:06 from Amir Schnabel:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:14 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:14 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:13 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:13 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:12 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:11 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:11 from Shlomo Grinshpon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:18 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:18 from Daniel Cohen (FAST INTERNET):Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Shmulik Shechter:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Shmulik Shechter:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:17 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Lev Shapiro:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Yehiel Etah:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:15 from Lev Shapiro:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:25 from Moshe Stein:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Uzi Drori:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Zohar Halachmi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Daniel Cohen (FAST INTERNET):Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:22 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:26 from Uzi Drori:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Lori Bernardi:FW: Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:42 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 17:41 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Gilad Tam:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/07 Feb 2000 18:18 from Eli Friedlander:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:22 from Yossi Friedman:Check this/LINKS21.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:21 from Yossi Friedman:Check this/LINKS21.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:17 from Yossi Friedman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 10:16 from Yossi Friedman:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 08:47 from Roy Kinamon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 08:46 from Roy Kinamon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 03:12 from Haim Kashi:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/08 Feb 2000 03:12 from Raz Herbst:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/09 Feb 2000 08:24 from Gilad Ayalon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst/Personal Folders/Deleted Items/09 Feb 2000 08:23 from Gilad Ayalon:Check this/LINKS2.VBS Infected: Virus.VBS.Freelink
C:\billslaptop\Outlook\outlook.pst Infected: Virus.VBS.Freelink
C:\Documents and Settings\default\Local Settings\Temp\12A.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Documents and Settings\default\Local Settings\Temp\1AA.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Documents and Settings\default\Local Settings\Temp\CF.tmp Infected: Backdoor.Win32.Afcore.cm
C:\Program Files\Aprps\CxtPls.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\Program Files\Aprps\CxtPls.exe Infected: Trojan-Downloader.Win32.Apropo.ag
C:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\BonziBuddy.zip/WCInst.exe Suspicious: Password-protected-EXE
C:\WINDOWS\All Users\Application Data\Spybot - Search & Destroy\Recovery\BonziBuddy.zip Suspicious: Password-protected-EXE
C:\WINDOWS\optimize.exe Infected: Trojan-Downloader.Win32.Dyfuca.ab
C:\WINDOWS\SYSTEM32\netdteht.dll Infected: Backdoor.Win32.Afcore.cm
C:\WINDOWS\SYSTEM32\w130713.Stub.exe Infected: Trojan-Downloader.Win32.Delmed.a

Scan process completed.



Logfile of HijackThis v1.99.1
Scan saved at 7:32:43 AM, on 9/6/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\My Documents\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ntdll.dll] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O4 - Global Startup: strings.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O12 - Plugin for .hpb: C:\PROGRA~1\INTERN~1\PLUGINS\nphpipb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.bro...in/Download.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalci...6.1.7_en_dl.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?312
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
  • 0

Advertisements


#17
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Run Hijack This and click on scan. The following items need to be fixed -

O4 - Global Startup: strings.exe
O16 - DPF: {4208FB4D-4E53-4F5A-BF7A-3E047DDB5281} (ActiveX Control) - http://www.icannnews.../ST/ActiveX.ocx


Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

Delete the files -

C:\Program Files\Aprps
C:\WINDOWS\optimize.exe
C:\WINDOWS\SYSTEM32\netdteht.dll
C:\WINDOWS\SYSTEM32\w130713.Stub.exe



Please Download the following tools to assist us in removing this infection!
  • Download WinPFind
    • Right Click the Zip Folder and Select "Extract All"
    • Extract it somewhere you will remember like the Desktop
    • Dont do anything with it yet!
  • Download Track qoo
    • Save it somewhere you will remember like the Desktop
Reboot into Safe Mode
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Doubleclick WinPFind.exe
  • Click "Start Scan"
  • It will scan the entire System, so please be patient!
  • Once the Scan is Complete
  • Go to the WinPFind folder
  • Locate WinPFind.txt
  • Place those results in the next post!
Reboot back to Normal Mode!

Double Click on "Track qoo.vbs"

Note - If you Antivirus has Script Blocking, you will get a Pop Up Windows asking you what to do. Allow this Entire Script to Run, its harmless!

Wait a few seconds and a notepad page will pop up, Copy & Paste those results and place them in the next post along with the results of WinPFind!
  • 0

#18
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Windows would not let me delete the netdteht.dll file. The error message indicated it was in use by Windows.

Here are the results of the two programs.



WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows 2000 Current Build: Service Pack 4 Current Build Number: 2195
Internet Explorer Version: 6.0.2800.1106

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...

Items found in C:\WINDOWS\hosts

web-nex 8/12/2005 2:14:28 PM 205 C:\WINDOWS\mnaho.dll
Umonitor 8/22/2005 2:41:34 PM 316416 C:\WINDOWS\vx2cleaner.dlx
ZepMon 8/22/2005 2:41:34 PM 316416 C:\WINDOWS\vx2cleaner.dlx
ad-w-a-r-e.com 8/22/2005 2:41:34 PM 316416 C:\WINDOWS\vx2cleaner.dlx

Checking %System% folder...
UPX! 12/9/2003 12:31:00 AM 11254 C:\WINDOWS\SYSTEM32\locate.com
Umonitor 6/19/2003 3:05:04 PM 529168 C:\WINDOWS\SYSTEM32\RASDLG.DLL
winsync 12/7/1999 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu

Checking %System%\Drivers folder and sub-folders...

Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
9/2/2005 8:34:14 PM H 742912 C:\WINDOWS\ShellIconCache
8/26/2005 1:52:46 PM H 3802 C:\WINDOWS\All Users\Application Data\AOL\AOLDiag\AOL\HostManager\Win32\2005707.1601.419728a\manifest.bin
8/26/2005 1:53:34 PM H 3802 C:\WINDOWS\All Users\Application Data\AOL\AOLDiag\AOL\ServiceHost\Win32\2005707.1601.419728a\manifest.bin
8/26/2005 1:50:48 PM S 66 C:\WINDOWS\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\4c4437d1627d85c265fdcbdec1f20460_dd7dcb02-5bfd-448b-b9f5-eb136cd956c3
8/12/2005 8:08:50 AM S 47 C:\WINDOWS\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\6d14e4b1d8ca773bab785d1be032546e_dd7dcb02-5bfd-448b-b9f5-eb136cd956c3
8/27/2005 8:59:04 AM S 49 C:\WINDOWS\All Users\Application Data\Microsoft\Crypto\RSA\S-1-5-18\d42cc0c3858a58db2db37658219e6400_dd7dcb02-5bfd-448b-b9f5-eb136cd956c3
8/23/2005 3:31:40 PM H 548864 C:\WINDOWS\Application Data\Microsoft\Windows\UsrClass.dat
8/23/2005 3:31:40 PM H 1024 C:\WINDOWS\Application Data\Microsoft\Windows\UsrClass.dat.LOG
9/7/2005 8:50:10 AM S 64 C:\WINDOWS\CSC\00000001
8/29/2005 10:02:42 AM S 64 C:\WINDOWS\CSC\00000002
8/12/2005 2:14:16 PM H 0 C:\WINDOWS\inf\oem14.inf
9/2/2005 8:38:28 PM H 1024 C:\WINDOWS\SYSTEM32\config\default.LOG
9/7/2005 8:54:02 AM H 1024 C:\WINDOWS\SYSTEM32\config\SAM.LOG
9/7/2005 8:52:10 AM H 1024 C:\WINDOWS\SYSTEM32\config\SECURITY.LOG
9/7/2005 8:56:42 AM H 1024 C:\WINDOWS\SYSTEM32\config\software.LOG
8/12/2005 8:08:50 AM HS 336 C:\WINDOWS\SYSTEM32\Microsoft\Protect\S-1-5-18\User\11dacb1e-ea6c-42a9-b1f6-3797b5da13f0
8/12/2005 8:08:50 AM HS 24 C:\WINDOWS\SYSTEM32\Microsoft\Protect\S-1-5-18\User\Preferred
9/2/2005 8:36:14 PM HS 192 C:\WINDOWS\TASKS\RUTASK.job
9/7/2005 8:50:12 AM H 6 C:\WINDOWS\TASKS\SA.DAT

Checking for CPL files...
Microsoft Corporation 12/7/1999 67344 C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 301328 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 237328 C:\WINDOWS\SYSTEM32\DESK.CPL
Microsoft Corporation 12/7/1999 128272 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 8/29/2002 8:14:40 AM 292352 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 12/7/1999 118032 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 12/7/1999 36112 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 10/30/2001 9:10:00 AM 75264 C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems 9/28/2004 9:26:02 PM 61555 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation 12/7/1999 122128 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 12/7/1999 303888 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 12/7/1999 17168 C:\WINDOWS\SYSTEM32\ncpa.cpl
NVIDIA Corporation 5/3/2002 10:06:00 AM 106496 C:\WINDOWS\SYSTEM32\nvtuicpl.cpl
Microsoft Corporation 12/7/1999 41232 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 41232 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 90896 C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc. 4/11/2001 1:22:06 PM 287232 C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 83216 C:\WINDOWS\SYSTEM32\sticpl.cpl
Microsoft Corporation 6/19/2003 3:05:04 PM 125712 C:\WINDOWS\SYSTEM32\SYSDM.CPL
Microsoft Corporation 12/7/1999 5904 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 6/8/2000 1:00:00 PM 15360 C:\WINDOWS\SYSTEM32\THEMES.CPL
Microsoft Corporation 12/7/1999 61200 C:\WINDOWS\SYSTEM32\timedate.cpl
WildTangent, Inc. 3/12/2004 4:53:44 PM 45056 C:\WINDOWS\SYSTEM32\wtcpl.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation 8/29/2002 8:14:40 AM 292352 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
IBM Corporation 9/23/1999 6:44:36 PM 94208 C:\WINDOWS\SYSTEM32\dllcache\mwcpa32.cpl
Microsoft Corporation 12/7/1999 41232 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 5/26/2005 4:16:30 AM 174360 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
12/27/2003 11:32:40 PM 1008 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\HPAiODevice(hp officejet v series) - 1.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...

Checking files in %USERPROFILE%\Startup folder...
11/14/2003 1:53:08 PM 452 C:\Documents and Settings\default\Start Menu\Programs\Startup\HotSync Manager.lnk

Checking files in %USERPROFILE%\Application Data folder...
3/12/2003 10:13:28 PM 0 C:\Documents and Settings\default\Application Data\dm.ini
8/23/2005 5:11:36 PM 39 C:\Documents and Settings\default\Application Data\Sskcwrd.dll
8/23/2005 9:16:00 AM 445990 C:\Documents and Settings\default\Application Data\Sskknwrd.dll

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
{53C74826-AB99-4d33-ACA4-3117F51D3788} = C:\WINDOWS\system32\SHELL32.DLL

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\mygtntxy
{4f1d93aa-27ee-41da-a218-4ae0610d1283} = C:\WINDOWS\system32\eadon.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} =
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D} = syncui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\NortonAntivirus
{067DF822-EAB6-11cf-B56E-00A0244D5087} = C:\Program Files\Norton AntiVirus\navshell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E} = C:\Program Files\ewido\security suite\context.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} =
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\shell32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= C:\WINDOWS\System32\docprop2.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7ab770c7-0e23-4d7a-8aa2-19bfad479829}
= C:\WINDOWS\system32\SHELL32.DLL
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{7f9609be-af9a-11d1-83e0-00c04fb6e984}
= %SystemRoot%\system32\faxshell.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
= C:\WINDOWS\System32\docprop2.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}
Yahoo! Companion BHO = C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
= C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7C554162-8CB7-45A4-B8F4-8EA1C75885F9}
AOL Toolbar Launcher = C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}
Google Toolbar Helper = c:\program files\google\googletoolbar1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINDOWS\System32\msdxm.ocx
{DE9C389F-3316-41A7-809B-AA305ED9D922} = AOL Toolbar : C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\WINDOWS\System32\msjava.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3369AF0D-62E9-4bda-8103-B4C75499B578}
ButtonText = AOL Toolbar :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
ButtonText = AIM : C:\Program Files\AIM95\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
ButtonText = Messenger : C:\PROGRA~1\MESSEN~1\MSMSGS.EXE

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{30D02401-6A81-11D0-8274-00C04FD5AE38}
Search Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File and Folders Search ActiveX Control = C:\WINDOWS\system32\shell32.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E61-B078-11D0-89E4-00C04FC9E26E}
Favorites Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E62-B078-11D0-89E4-00C04FC9E26E}
History Band = %SystemRoot%\System32\shdocvw.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{EFA24E64-B078-11D0-89E4-00C04FC9E26E}
Explorer Band = %SystemRoot%\System32\shdocvw.dll

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{EF99BD32-C1FB-11D2-892F-0090271D4F88} = Yahoo! Companion : C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
{2318C2B1-4965-11D4-9B18-009027A5CD4F} = &Google : c:\program files\google\googletoolbar1.dll
{DE9C389F-3316-41A7-809B-AA305ED9D922} = AOL Toolbar : C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\System32\browseui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
SystemTray SysTray.Exe
Synchronization Manager mobsync.exe /logon
NvCplDaemon RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
nwiz nwiz.exe /install
WorksFUD C:\Program Files\Microsoft Works\wkfud.exe
Microsoft Works Portfolio C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
Adaptec DirectCD C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
QuickTime Task "C:\Program Files\QuickTime\qttask.exe" -atboottime
CamMonitor C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
Share-to-Web Namespace Daemon C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
SunJavaUpdateSched C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
HostManager C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
ntdll.dll "C:\Program Files\QuickTime\qttask.exe" -atboottime

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
MSMSGS C:\PROGRA~1\MESSEN~1\msmsgs.exe /background

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\AdminComponent

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 149
CDRAutoRun 0


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
Network.ConnectionTray {7007ACCF-3202-11D1-AAD2-00805FC1270E} = C:\WINDOWS\system32\NETSHELL.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = explorer.exe
System =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
= wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.5 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/7/2005 9:18:52 AM







REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemTray"="SysTray.Exe"
"Synchronization Manager"="mobsync.exe /logon"
"NvCplDaemon"="RUNDLL32.EXE NvQTwk,NvCplDaemon initialize"
"nwiz"="nwiz.exe /install"
"WorksFUD"="C:\\Program Files\\Microsoft Works\\wkfud.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Adaptec DirectCD"="C:\\PROGRA~1\\Adaptec\\DirectCD\\directcd.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"CamMonitor"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\\\Unload\\hpqcmon.exe"
"Share-to-Web Namespace Daemon"="C:\\Program Files\\Hewlett-Packard\\HP Share-to-Web\\hpgs2wnd.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\jusched.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1125078722\\ee\\AOLHostManager.exe"
"ntdll.dll"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

-----------------
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers


Subkey --- BriefcaseMenu
{85BBD920-42A0-1069-A2E4-08002B30309D}
syncui.dll

Subkey --- ewido
{57BD36D7-CE32-4600-9B1C-1A0C47EFC02E}
C:\Program Files\ewido\security suite\context.dll

Subkey --- mygtntxy
{4f1d93aa-27ee-41da-a218-4ae0610d1283}
C:\WINDOWS\system32\eadon.dll

Subkey --- Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03}


Subkey --- Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936}
C:\WINDOWS\system32\shell32.dll

Subkey --- Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46}
C:\WINDOWS\system32\shell32.dll

Subkey --- WinZip
{E0D79304-84BE-11CE-9641-444553540000}
C:\PROGRA~1\WINZIP\WZSHLSTB.DLL

=====================

HKEY_CLASSES_ROOT\Folder\shellex\ColumnHandlers


Subkey --- {0D2E74C4-3C34-11d2-A27E-00C04FC30871}
C:\WINDOWS\system32\shell32.dll

Subkey --- {24F14F01-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\shell32.dll

Subkey --- {24F14F02-7B1C-11d1-838f-0000F80461CF}
C:\WINDOWS\system32\shell32.dll

Subkey --- {66742402-F9B9-11D1-A202-0000F81FEDEE}
C:\WINDOWS\System32\docprop2.dll

Subkey --- {7ab770c7-0e23-4d7a-8aa2-19bfad479829}
C:\WINDOWS\system32\SHELL32.DLL

Subkey --- {7f9609be-af9a-11d1-83e0-00c04fb6e984}
C:\WINDOWS\system32\faxshell.dll

Subkey --- {884EA37B-37C0-11d2-BE3F-00A0C9A83DA1}
C:\WINDOWS\System32\docprop2.dll

==============================
C:\Documents and Settings\All Users\Start Menu\Programs\Startup

HPAiODevice(hp officejet v series) - 1.lnk
==============================
C:\Documents and Settings\default\Start Menu\Programs\Startup

HPAiODevice(hp officejet v series) - 1.lnk
HotSync Manager.lnk
==============================
C:\WINDOWS\SYSTEM32 cpl files


access.cpl Microsoft Corporation
appwiz.cpl Microsoft Corporation
DESK.CPL Microsoft Corporation
hdwwiz.cpl Microsoft Corporation
inetcpl.cpl Microsoft Corporation
intl.cpl Microsoft Corporation
irprops.cpl Microsoft Corporation
joy.cpl Microsoft Corporation
jpicpl32.cpl Sun Microsystems
main.cpl Microsoft Corporation
mmsys.cpl Microsoft Corporation
ncpa.cpl Microsoft Corporation
nvtuicpl.cpl NVIDIA Corporation
nwc.cpl Microsoft Corporation
odbccp32.cpl Microsoft Corporation
powercfg.cpl Microsoft Corporation
QuickTime.cpl Apple Computer, Inc.
sticpl.cpl Microsoft Corporation
SYSDM.CPL Microsoft Corporation
telephon.cpl Microsoft Corporation
THEMES.CPL Microsoft Corporation
timedate.cpl Microsoft Corporation
wtcpl.cpl WildTangent, Inc.
wuaucpl.cpl Microsoft Corporation
  • 0

#19
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Download Pocket KillBox from here. There is a Direct Download and a description of what the Program does inside this link.

Please open Notepad, and copy/paste the code in the box below into a new text file. Save it as KillQoo.reg (set Filetype to "All Files") and save it on your Desktop.

REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\mygtntxy]

[-HKEY_CLASSES_ROOT\CLSID\{4f1d93aa-27ee-41da-a218-4ae0610d1283}]


Open Pocket Killbox and Copy & Paste the entries below into the "Full Path of File to Delete"

C:\WINDOWS\mnaho.dll
C:\Documents and Settings\default\Application Data\Sskcwrd.dll
C:\Documents and Settings\default\Application Data\Sskknwrd.dll
C:\WINDOWS\system32\eadon.dll
C:\WINDOWS\SYSTEM32\netdteht.dll


As you Paste each entry into Killbox,place a tick by any of these Selections available

"Delete on Reboot"
"Unregister .dll before Deleting"


Click the Red Circle with the White X in the Middle to Delete!

Restart in Safe Mode and Run those files through Killbox once more to be sure nothing survived.

This time place a tick by any of these selections available

"Standard File Kill"
"End Explorer Shell while Killing File"
"Unregister .dll before Deleting"


Now Locate and DoubleClick KillQoo.reg-> Allow it to merge into the Registry!

Restart back in Normal Mode and Post a fresh HijackThis log!
  • 0

#20
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
I think all the files are gone.


Logfile of HijackThis v1.99.1
Scan saved at 5:21:11 PM, on 9/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1125078722\ee\AOLServiceHost.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\My Documents\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [ntdll.dll] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O12 - Plugin for .hpb: C:\PROGRA~1\INTERN~1\PLUGINS\nphpipb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.bro...in/Download.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalci...6.1.7_en_dl.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?312
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
  • 0

#21
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
yes all the bad files seem to have been taken care of.


Do you have any issues with your PC ?? Also let me know if you are using trial version of Ewido or you have subscribed to it !!!!!

If not then we can fine tune your PC.
  • 0

#22
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Hi Tampabelle,

PC is working great!
I also noticed the fan is no longer running constantly. A whole lot less CPU utilization.

I am using a trial version of Ewido.

I'm ready to fine tune.

Thanks.
  • 0

#23
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
The fan is not running or you can hear the fan running ???

The fan is supposed to run continuously !!!! If it doesnt then the PC / Power source may heat up and cause itself damage. Please check the physical connections. If required please have the PC inspected (if the fan is not running continuously).


Delete the following programs and the associated folders, which you downloaded during the cleaning up process -

CWShredder
dsrfix.zip
Nailfix.exe
l2mfix.exe
Winpfind.zip
Trackqoo.vbs
Killbox.exe

dsrfix folder
l2mfix folder
WinPfind folder
!submit folder




Uninstall Ewido as it is a trial product and the trial period will expire shortly. Conflicts can arise between multiple anti-virus programs and can severely hamper the performance of the PC.

Download and install - AVG Anti-Virus --- freeware

Run Hijack This and click on scan. The following items need to be fixed -

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ntdll.dll] "C:\Program Files\QuickTime\qttask.exe" -atboottime


Close all windows other than Hijack This. Check the boxes next to above items and click on Fix checked.

This will not delete the programs from your PC. This will only disable the programs from running at Start up and result in a faster PC. You can always run the programs manually by using the respective exe files or the shortcuts.

After this, please visit Windows security and critical updates and get all the updates and patches and install them on your PC.

Reboot the PC and post a fresh HJT log.
  • 0

#24
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
No worries. Fan is still running! (but it must have been running faster before because i swear it was louder)

Updated and HJT log below.

Logfile of HijackThis v1.99.1
Scan saved at 7:01:29 PM, on 9/9/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\regsvc.exe
C:\WINDOWS\system32\MSTask.exe
C:\WINDOWS\system32\stisvc.exe
C:\WINDOWS\System32\WBEM\WinMgmt.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\PROGRA~1\MESSEN~1\msmsgs.exe
C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\AOL\1125078722\ee\AOLServiceHost.exe
C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOSTS07.exe
C:\Program Files\Hewlett-Packard\AiO\Shared\bin\hpOFXM07.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\My Documents\Hijack\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_10_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Adaptec DirectCD] C:\PROGRA~1\Adaptec\DirectCD\directcd.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1125078722\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [MSMSGS] C:\PROGRA~1\MESSEN~1\msmsgs.exe /background
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HPAiODevice(hp officejet v series) - 1.lnk = C:\Program Files\Hewlett-Packard\AiO\hp officejet v series\Bin\hpoant07.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\MESSEN~1\MSMSGS.EXE
O9 - Extra button: Dell Home - {08DCFC6C-B6E4-480C-95A4-FC64F37B787E} - http://www.dellnet.com/ (file missing) (HKCU)
O12 - Plugin for .hpb: C:\PROGRA~1\INTERN~1\PLUGINS\nphpipb.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft...free/asinst.cab
O16 - DPF: {B160422D-0A48-11D4-BD9B-00A0C9B0AB7B} (Download Class) - http://expressit.bro...in/Download.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalci...6.1.7_en_dl.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.h.../qdiagh.cab?312
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
  • 0

#25
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Hi,



CONGRATULATIONS !!!!!!!!!!! Your PC is clean now :tazz:



I would recommend the following steps to keep your PC clean –

PREVENTIVE MEASURES FOR FUTURE

Operating System
1. Keep the Windows and Internet Explorer updated with the latest fixes. These fixes are available free from Microsoft. Click on Tools in the IE menu bar and then on Windows update. You can also use the following links

Windows security and critical updates
Internet Explorer security and critical updates

Also ensure that automatic updates are enabled for faster updation of the system.
(Right click on My Computer on your desktop, properties and Automatic Updates tab.


Anti-Virus Software
2. Keep your Anti-virus program updated with the latest definitions. Some of the common anti-virus programs in use are :

Norton Anti-Virus
McAfee Anti-Virus
AVG Anti-Virus --- freeware
Avast Home Edition --- freeware

Use only one anti-virus program as multiple such programs can create conflicts between themselves and severely hamper the performance of your PC.


Firewall
3. You should also have a good firewall. Here are 3 free ones available for personal use:
Sygate Personal Firewall, Kerio Personal Firewall, ZoneAlarm


Internet Browsers
4. Have robust explorer settings. It is preferable to use an internet browser other that IE as most of the malware is targetted at IE. In case you prefer to use IE, then download a list of innocent looking but harmful websites from IE-Spyad and install it on ur PC. IE-SPYAD puts over 5000 sites in your internet explorer's restricted zone, so you'll be protected when you visit innocent-looking sites that aren't really innocent at all.

Some alternate browsers I suggest are Firefox Mozilla Browser and Opera

Ensure that Security level, irrespective of whichever browser you use, is set at Medium or higher, restrict the usage of cookies and activeX components.


Spyware Protection
5. Have a wall of protection against spyware / adware by installing SpywareBlaster and SpywareGuard.

SpywareBlaster and SpywareGuard are by JavaCool and both are free programs.
SpywareBlaster will prevent spyware from being installed and consumes no system resources.
SpywareGuard offers realtime protection from spyware installation and browser hijack attempts. Both have free ongoing updates.


Spyware Removers
6. Install programs for scanning for malware and uninstalling them. Two of the best programs, both are freeware, are :

Spybot Search & Destroy - A powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.

AdAware SE Personal Edition - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.


Regular Maintenance of PC
7. Finally, invest some time for regular maintenance of your PC. Delete the temporary Internet files, temporary files, cookies etc. Click on Start button, Programs, Accessories, System Tools and run the program Disk Cleanup. Follow the instructions.

An alternate freeware software which can be used is CleanUp.

Keep your Registry clean. My favourite software is Registry First Aid. This is not a freeware but a trial version can be downloaded.




Go ahead and enjoy a clean PC !!!!!!!!!!!!!
  • 0

Advertisements


#26
wldorsey

wldorsey

    Member

  • Topic Starter
  • Member
  • PipPip
  • 20 posts
Tampabelle, thanks so much for your expert assistance. My PC continues to operate very efficiently.

I've made a contribution as a small token of appreciation.

Thanks again and I look forward to working with you on my next project ... tackleing my daughter's laptop.
  • 0

#27
tampabelle

tampabelle

    Member 5k

  • Retired Staff
  • 6,363 posts
Thanx for your contribution.

Sure post your daughter's logs and let me know.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP