Hi g2i2r4,
Here are the results
ACTIVESCAN LOG:Incident Status Location
Spyware:spyware/bridge No disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\bridge.inf
Spyware:spyware/betterinet No disinfected C:\WINDOWS\INF\biini.inf
Adware:adware/twain-tech No disinfected C:\WINDOWS\smdat32a.sys
Spyware:spyware/altnet No disinfected C:\PROGRAM FILES\Altnet
Adware:adware/topmoxie No disinfected C:\PROGRAM FILES\couponsandoffers
Adware:adware/sidesearch No disinfected C:\PROGRAM FILES\Lycos
Adware:adware/myway No disinfected C:\PROGRAM FILES\MyWay
Adware:adware/quicksearch No disinfected C:\PROGRAM FILES\QuickSearch
Adware:adware/blazefind No disinfected Windows Registry
Virus:W32/Lentin.R Disinfected Hotmail\Inbox\The world of Friendship\world_of_friendship.scr
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Vidhya\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\counter.jar-7271642a-5145c6af.zip[Beyond.class]
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\a.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\b.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ba.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bb.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bc.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bd.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\be.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\bf.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bg.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\bh.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bi.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bj.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\bk.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bl.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bm.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bn.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\bo.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\bp.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bq.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\br.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bs.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bt.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bu.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bv.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bw.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bx.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\by.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\bz.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\c.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ca.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cb.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cc.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cd.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\ce.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cf.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cg.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ch.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ci.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cj.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ck.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cl.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cm.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cn.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\co.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cp.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\cq.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\cr.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cs.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\ct.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cu.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cv.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\cx.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\cz.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\d.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\da.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\db.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dc.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dd.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\de.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\df.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\di.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dl.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\dn.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\dp.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dr.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ds.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dt.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\du.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dv.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\dw.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\dy.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\dz.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\ed.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\f.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\h.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\i.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\j.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\l.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\m.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\n.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\p.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\q.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\r.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\s.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\t.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\u.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\w.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\couponsandoffers\System\Code\x.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\couponsandoffers\System\Code\y.class
Spyware:Spyware/New.net No disinfected C:\Program Files\FileSubmit\My Light In Darkness\NNEZTA388.exe
Adware:Adware/QuickSearch No disinfected C:\Program Files\FileSubmit\My Light In Darkness\TBEZA127Q.exe
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\LimeShop.exe
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\a.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\LimeShop\System\Code\bf.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\bq.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\LimeShop\System\Code\bs.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dc.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dm.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\du.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dx.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\i.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\j.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\p.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\q.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\s.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\t.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\u.class
Adware:Adware/QuickSearch No disinfected C:\Program Files\QuickSearch\QuickSearchBar1_27.dll
Adware:Adware/WUpd No disinfected C:\Program Files\support.com\backup\CD\CD2B013Bd01\24712_56bd76541_[CD2B013Bd01]
Adware:Adware/NetPals No disinfected C:\WINDOWS\iNetPal\m3tsp8.exe
Spyware:Spyware/BetterInet No disinfected C:\WINDOWS\inf\biini.inf
Adware:Adware/Startpage.FG No disinfected C:\WINDOWS\system32\mtwirl.dll
HijackThis Log:Logfile of HijackThis v1.99.1
Scan saved at 3:37:06 PM, on 9/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\dvd43\dvd43_tray.exe
C:\Program Files\Winamp\winampa.exe
C:\Utils\ZoneAlarm\zlclient.exe
C:\Utils\Eraser\historyeraser.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\PROGRA~1\Logitech\Video\AlbumDB2.exe
C:\PROGRA~1\Logitech\Video\FxSvr2.exe
C:\Utils\Hijackthis\HijackThis.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Utils\Anti-Spyware\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Download - {777D0B4C-75C9-4874-ABFF-80B4BE8DC532} - C:\Program Files\Download Toolbar\IEBand2.dll
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Utils\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [HD] C:\Utils\Jvw History Eraser and IE Panic 1.0 Trial\Hd.cmd
O4 - HKCU\..\Run: [BackupNotify] C:\Program Files\HP\Digital Imaging\bin\backupnotify.exe
O4 - HKCU\..\Run: [SPSTEALT] "C:\Utils\Eraser\historyeraser.exe" /stealt
O8 - Extra context menu item: Download using LeechGet - file://C:\Utils\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: Download using LeechGet Wizard - file://C:\Utils\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: Parse with LeechGet - file://C:\Utils\LeechGet 2004\\Parser.html
O8 - Extra context menu item: Save To Gallery - res://C:\Program Files\Download Toolbar\IEBand2.dll/DownloadToGallery.htm
O9 - Extra button: ComcastHSI - {669B269B-0D4E-41FB-A3D8-FD67CA94F646} -
http://www.comcast.net/ (file missing)
O9 - Extra button: Support - {8828075D-D097-4055-AA02-2DBFA9D85E8A} -
http://www.comcastsupport.com/ (file missing)
O9 - Extra button: Help - {97809617-3937-4F84-B335-9BB05EF1A8D4} -
http://online.comcast.net/help/ (file missing)
O9 - Extra button: (no name) - {AFC3FA82-AD07-45cd-8B57-983435B9899E} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) -
http://www.vikatan.com/tdserver.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO20 - Winlogon Notify: WB - C:\MACOSG~1\WINDOW~1\WINDOW~1\fastload.dll
O23 - Service: Ensemble [ENSEMBLE] (Cache_c-_ensemblesys) - Unknown owner - c:\ensemblesys\bin\cservice.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
VundoFix Log:Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP
V2.03
Copyright© 2002-2003
[email protected]Suspending PID 264 'smss.exe'
Threads [268][272][276]
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP
V2.03
Copyright© 2002-2003
[email protected]Killing PID 900 'explorer.exe'
Killing PID 900 'explorer.exe'
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP
V2.03
Copyright© 2002-2003
[email protected]Error, Cannot find a process with an image name of rundll32.exe
Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP
V2.03
Copyright© 2002-2003
[email protected]Killing PID 340 'winlogon.exe'
Killing PID 340 'winlogon.exe'
Error 0x5 : Access is denied.File Deleted sucessfully.
Files Deleted sucessfully.
I wanted to tell you about a few things I encountered.
I didn't have the Resident Uncheck Teatimer box and/or Uncheck Resident since when I went to the 'Tools' dialog I saw only an 'Install' link to install the Resident tools.
Also in HijackThis V1.99.1, I couldn't find the Box that says "Uninstall Manager"- "SpyKiller". So I just closed both the programs. Would that be a problem since I didn't have these?
I appreciate your help a lot.
Thanks,
jimbono