1st, i wasn't able to find this file: C:\WINDOWS\q42626914_disk.dll
and here are my logs:Active scan:Incident Status Location
Adware:adware/startpage.bbc No disinfected C:\w.exe
Logfile of HijackThis v1.99.1
Scan saved at 4:53:10, on 5.9.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\hijack this\HijackThis.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1124407770261O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO21 - SSODL: AutoCAD 2000 Uninstall - {3CBD884E-6B25-5AD0-FCBC-D377EE3BFDF7} - c:\progra~1\acad2000\winhnnc5.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Program Files\Eset\nod32krn.exe
smitRem log file
version 2.3
by noahdfear
The current date is: pon 05.09.2005
The current time is: 2:44:18,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ShudderLTD key present! Running LTDFix!
ShudderLTD key was successfully removed!
Pre-run Files Present
~~~ Program Files ~~~
PSGuard
~~~ Shortcuts ~~~
PSGuard spyware remover
PSGuard spyware remover.lnk
quick launch PSGuard spyware remover.lnk
~~~ Favorites ~~~
Online Gambling.url
online dating.url
Online Dating.url
~~~ system32 folder ~~~
oleext.dll
wppp.html
intmonp.exe
ole32vbs.exe
hp***.tmp
shnlog.exe
intmon.exe
hhk.dll
logfiles
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
sites.ini
popuper.exe
~~~ Drive root ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
oleext.dll
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Wininet.dll ~~~
wininet.dll INFECTED!!
Starting replacement procedure.
~~~~ Looking for C:\WINDOWS\system32\dllcache\wininet.dll ~~~~
~~~~ dllcache\wininet.dll not present! ~~~~
~~~~ Looking for C:\WINDOWS\$hf_mig$\KB890923\SP2QFE\wininet.dll ~~~~
~~~~ KB890923\SP2QFE\wininet.dll not present! ~~~~
~~~~ Looking for C:\WINDOWS\$hf_mig$\KB867282\SP2QFE\wininet.dll ~~~~
~~~~ KB867282\SP2QFE\wininet.dll not present! ~~~~
~~~~ Looking for C:\WINDOWS\$hf_mig$\KB883939\SP2QFE\wininet.dll ~~~~
~~~~ KB883939\SP2QFE\wininet.dll not present! ~~~~
~~~~ Looking for C:\WINDOWS\ServicePackFiles\i386\wininet.dll ~~~~
~~~~ C:\WINDOWS\ServicePackFiles\i386\wininet.dll Present! ~~~~
~~~~ Checking C:\WINDOWS\ServicePackFiles\i386\wininet.dll for infection ~~~~
~~~~ ServicePackFiles\i386\wininet.dll Clean! ~~~~
~~~ Replaced wininet.dll from ServicePackFiles\i386 ~~~
~~~ Upon reboot ~~~
wininet.old present!
oleadm.dll not present!
oleext.dll not present!
~~~ Upon completion ~~~
wininet.old not present!
oleadm.dll not present!
oleext.dll not present!
~~~~ Rechecking C:\WINDOWS\system32\wininet.dll for infection ~~~~
~~~~ C:\WINDOWS\system32\wininet.dll Clean!
~~~~
---------------------------------------------------------
ewido security suite - Scan report
--------------------------------------------------------- + Created on: 3:43:29, 5.9.2005
+ Report-Checksum: DFBE7132
+ Scan result:
[220] C:\WINDOWS\q42626914_disk.dll -> TrojanDownloader.Delf.lh : Cleaned with backup
[264] C:\WINDOWS\system32\OLEEXT.dll -> Trojan.Agent.ff : Cleaned with backup
[556] C:\WINDOWS\system32\OLEEXT.dll -> Trojan.Agent.ff : Error during cleaning
[932] C:\WINDOWS\q42626914_disk.dll -> TrojanDownloader.Delf.lh : Error during cleaning
:mozilla.10:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Trafic : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.114:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Ivwbox : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.137:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Andy\Application Data\Mozilla\Firefox\Profiles\1ctmxxyt.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\03E2B301-E36B-41E2-BE90-2FEA30\916920E7-236D-4F6C-8AC6-E4D438 -> Trojan.Small.ev : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\B7ADEFA5-2443-46AF-9783-9386BE\6C2EA613-09D3-4D38-BA0B-E6ACEA -> Trojan.Small.ev : Cleaned with backup
C:\WINDOWS\q42626914_disk.dll -> TrojanDownloader.Delf.lh : Cleaned with backup
C:\WINDOWS\system32\mfmh.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\system32\oleext.dll -> Trojan.Small.ev : Cleaned with backup
::Report End
It, seems to be working just fine, now..
Thank you!!
Edited by mirella, 04 September 2005 - 09:04 PM.