back at last - terribly sorry about that!
Things are working for the moment!
There was already an rdriv.txt file in the folder. I forgot to check it before running the program, so I don't know if it was replaced. This is what it is now:
"
~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~
~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~
~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~
~~~~~~~~~~~~~ Pre-run File Check ~~~~~~~~~~~~~
rdriv.sys present!
windupdate.exepresent!
~~~~~~~~~~~~~ Post run File Check ~~~~~~~~~~~~~ "
ewido:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 9:28:59 PM, 9/25/2005
+ Report-Checksum: 7054C559
+ Scan result:
:mozilla.10:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\l2toyw4w.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\WINDOWS\system32\drivers\etc\systemp\servicesnt.exe -> Backdoor.SdBot.nj : Cleaned with backup
C:\WINDOWS\system32\drivers\etc\winpit4.exe/kill.exe -> Trojan.KillApp.d : Error during cleaning
C:\WINDOWS\system32\drivers\etc\winpit4.exe/servicesnt.exe -> Backdoor.SdBot.nj : Error during cleaning
C:\WINDOWS\system32\eraseme_01756.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_64768.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_65712.exe -> Backdoor.SdBot.xd : Cleaned with backup
C:\WINDOWS\system32\eraseme_82766.exe -> Backdoor.SdBot.xd : Cleaned with backup
::Report End
I couldn't find a place to get a report from activescan, but it found no "viruses or other malicious software".
Hijack This:
Logfile of HijackThis v1.99.1
Scan saved at 1:02:33 PM, on 9/28/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\System32\Atievxx.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Updater.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HijackThis.exe
C:\WINDOWS\System32\imapi.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft...free/asinst.cabO16 - DPF: {C606BA60-AB76-48B6-96A7-2C4D5C386F70} (PreQualifier Class) - file://D:\Bin\html\files\MotivePreQual.cab
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: servicesnt Service: spoolntA (spoolntA) - Unknown owner - C:\WINDOWS\system32\drivers\etc\systemp\servicesnt.EXE (file missing)
O23 - Service: servicesnt Service: svchostntA (svchostntA) - Unknown owner - C:\WINDOWS\system32\drivers\etc\systemp\servicesnt.EXE (file missing)
thankyouthankyou