Hi, i think Ive done everyting you said properly.
Here are the logs you asked me to post.
This is the Panda ActiveScan log:Incident Status Location
Adware:adware/adsmart No disinfected C:\WINDOWS\SYSTEM32\vxgamet2.exe
Adware:adware/fastvideoplayer No disinfected C:\WINDOWS\INF\fvp.inf
Adware:adware/gator No disinfected C:\WINDOWS\GatorPdpLoudInstaller.log
Dialer:dialer.su No disinfected C:\WINDOWS\run.cxq
Adware:adware/twain-tech No disinfected C:\WINDOWS\smdat32a.sys
Adware:adware/comet No disinfected C:\PROGRAM FILES\Starware
Adware:adware/ilookup No disinfected C:\WINDOWS\iLookup
Adware:adware/spysheriff No disinfected Windows Registry
Virus:Trj/Classloader.I Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-690cc978-559a184a.zip[b.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-690cc978-559a184a.zip[c.class]
Virus:Exploit/BytVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-690cc978-559a184a.zip[a.class]
Virus:Trj/Downloader.DIS Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-690cc978-559a184a.zip[d.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-f336957-2aaf41ca.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-f336957-2aaf41ca.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-f336957-2aaf41ca.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-f336957-2aaf41ca.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-36e34e2f-2f682dc1.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-36e34e2f-2f682dc1.zip[Xeyond.class]
Virus:Trj/Downloader.APT Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\Counters.jar-36e34e2f-2f682dc1.zip[web.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[Worker.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[Xeyond.class]
Virus:Trj/Clicker.AH Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-207f0ae5.zip[web.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[Counter.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[Gummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[VerifierBug.class]
Virus:Trj/LowZones.JF Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[web.exe]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[Worker.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Saint Stuart\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-2a251b3-75a0eccc.zip[Xeyond.class]
Dialer:Dialer.DIM No disinfected C:\Documents and Settings\Saint Stuart\Local Settings\Temp\delwbi.tmp
Dialer:Dialer.BEW No disinfected C:\Documents and Settings\Saint Stuart\Local Settings\Temporary Internet Files\Content.IE5\0DIBKTUF\access[1].htm
Adware:Adware/WeatherCast No disinfected C:\Program Files\MyEmoticons\VVSNI_S3_MYEM_Inst.exe
Possible Virus. No disinfected C:\WINDOWS\Downloaded Program Files\910000_211348_.exe130
Adware:Adware/Fastvideoplayer No disinfected C:\WINDOWS\Downloaded Program Files\fvp.inf
Adware:Adware/ISearch No disinfected C:\WINDOWS\HLInstaller1.exe
Adware:Adware/eZula No disinfected C:\WINDOWS\iLookup\ezStub22.exe
Adware:Adware/Fastvideoplayer No disinfected C:\WINDOWS\inf\fvp.inf
Dialer:Dialer.AAR No disinfected C:\WINDOWS\mmgr32.exe
Dialer:Dialer.SU No disinfected C:\WINDOWS\run.cxq
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1031.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1033.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1034.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1136.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1139.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1143.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1322.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1323.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1324.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1340.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1341.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1342.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys141.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys145.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys146.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys147.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1827.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1828.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1832.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1833.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1854.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1915.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys1916.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys210.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2147.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2148.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2219.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2220.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2221.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2241.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2242.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2248.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2249.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys25.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys250.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys251.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2536.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2537.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2539.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2559.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys256.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys258.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2615.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2616.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2617.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2726.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2727.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2810.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2811.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys288.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys29.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys2912.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys343.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys5214.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys5226.exe
Virus:Trj/Downloader.DWG Disinfected C:\WINDOWS\sys5229.exe
Adware:Adware/InstaFinder No disinfected C:\WINDOWS\system32\InstaFinder_inst245.exe
Security Risk:Application/RestartNo disinfected C:\WINDOWS\system32\Tools\Restart.exe
Adware:Adware/Tibs No disinfected C:\WINDOWS\system32\vxgamet2.exe
Virus:Bck/Galapoper.B Disinfected C:\WINDOWS\system32\~update.exe
This is the smitfiles.txt log:smitRem log file
version 2.6
by noahdfear
The current date is: 14/10/2005
The current time is: 20:35:30.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
Pre-run Files Present
~~~ Program Files ~~~
SpySheriff
~~~ Shortcuts ~~~
Install.dat
~~~ Favorites ~~~
~~~ system32 folder ~~~
zlbw.dll
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
desktop.html
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Post-run Files Present
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
This is the Ewido Log:---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 21:42:48, 14/10/2005
+ Report-Checksum: 93173E14
+ Scan result:
C:\Documents and Settings\Comet Stockport\My Documents\HijackThis DONT DELETE\backups\backup-20051014-201653-678.dll -> Spyware.Comet : Ignored
C:\Program Files\MyEmoticons\VVSNI_S3_MYEM_Inst.exe -> Adware.SaveNow : Ignored
C:\Program Files\WinFixer 2005 -> Spyware.WinFixer : Ignored
C:\Program Files\WinFixer 2005\lock.dat -> Spyware.WinFixer : Ignored
C:\WINDOWS\HLInstaller1.exe -> Spyware.iSearch : Ignored
C:\WINDOWS\iLookup -> Adware.eZula : Ignored
C:\WINDOWS\iLookup\ezStub22.exe -> Adware.eZula : Ignored
C:\WINDOWS\mmgr32.exe -> Dialer.Generic : Ignored
C:\WINDOWS\sys1031.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1033.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1034.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1136.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1139.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1143.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1322.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1323.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1324.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1340.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1341.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1342.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys141.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys145.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys146.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys147.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1827.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1828.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1832.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1833.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1854.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1915.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys1916.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys210.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2147.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2148.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2219.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2220.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2221.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2241.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2242.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2248.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2249.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys25.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys250.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys251.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2536.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2537.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2539.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2559.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys256.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys258.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2615.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2616.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2617.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2726.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2727.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2810.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2811.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys288.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys29.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys2912.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys343.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys5214.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys5226.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\sys5229.exe -> Trojan.Crypt.i : Ignored
C:\WINDOWS\system32\vxgamet2.exe -> TrojanDownloader.Small.aqu : Ignored
C:\WINDOWS\system32\~update.exe -> Trojan.Crypt.c : Ignored
C:\Program Files\Starware\bin\Starware.dll -> Spyware.Starad : Cleaned with backup
C:\vx.tllllsl -> Adware.SpySheriff : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\miniclipGameLoader.dll -> TrojanDownloader.Small : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup
C:\WINDOWS\HotPorn.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\iNetPal\EZThemes_If245Om1.exe -> TrojanDropper.Small.sc : Cleaned with backup
C:\WINDOWS\sys148.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1518.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1519.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1521.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1736.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1737.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1738.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1826.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1834.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1848.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1850.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys1917.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys202.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys203.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys204.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2238.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2239.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2240.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2250.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2411.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys245.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys249.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2541.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2542.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2548.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2549.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2551.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2556.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2557.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys257.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2913.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2914.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2919.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2920.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys2921.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3037.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3038.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3039.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3119.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3121.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3123.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3124.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3239.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3240.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys341.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3415.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3417.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys342.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3424.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3559.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys361.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys363.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3840.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3843.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3846.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3853.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3855.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys3856.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4243.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys431.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys432.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys458.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys459.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4610.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4611.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4810.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4811.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4812.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4818.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4820.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys4822.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys50.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5033.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5034.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5035.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys511.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys512.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys513.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5148.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5150.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5151.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5212.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5213.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys527.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys528.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys529.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys530.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys531.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5311.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5330.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5338.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5339.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5340.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5342.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5725.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5726.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5727.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5816.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5817.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys5818.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys931.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys934.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\sys937.exe -> Trojan.Crypt.i : Cleaned with backup
C:\WINDOWS\system32\drivers\df_kmd.sys -> Trojan.Rootkit.Agent.af : Cleaned with backup
C:\WINDOWS\system32\drivers\etc\hosts -> Trojan.Qhost.r : Cleaned with backup
C:\WINDOWS\system32\DummyX.dll -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\emake2b.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\fvp.dll -> TrojanDownloader.Agent.oc : Cleaned with backup
C:\WINDOWS\system32\latest.exe -> Trojan.Crypt.c : Cleaned with backup
C:\WINDOWS\system32\mmgr32.exe -> Dialer.Generic : Cleaned with backup
C:\WINDOWS\system32\sgf.exe -> Not-A-Virus.Hoax.Renos.f : Cleaned with backup
C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
C:\WINDOWS\wt\wtvh.dll -> Spyware.WildTangent : Cleaned with backup
::Report End
And this is the new HijackThis Log :Logfile of HijackThis v1.99.1
Scan saved at 12:12:27, on 15/10/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\CA\eTrust Antivirus\InoRpc.exe
C:\Program Files\CA\eTrust Antivirus\InoRT.exe
C:\Program Files\CA\eTrust Antivirus\InoTask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\SLEE503.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Icons\Seticon.exe
C:\PROGRA~1\CA\ETRUST~1\realmon.exe
C:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Menu\SonyTray.exe
C:\Program Files\Sony Corporation\Picture Package\Picture Package Applications\Residence.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\SURFCO~1\CYBERP~1\cpserver.exe
C:\Documents and Settings\Comet Stockport\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.uk/R3 - URLSearchHook: (no name) - <default> - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: eBay Toolbar Helper - {22D8E815-4A5E-4DFB-845E-AAB64207F5BD} - C:\Program Files\eBay\eBay Toolbar2\eBayTB.dll
O2 - BHO: Miniclip - {4E7BD74F-2B8D-469E-89B3-BE29F5D3E32D} - C:\PROGRA~1\MINICL~1\MINICL~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [CyberPatrolNew] C:\Program Files\SurfControl\CyberPatrol\cphq.exe /m
O4 - HKLM\..\Run: [Seticon] C:\Program Files\Icons\Seticon.exe
O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s
O4 - HKLM\..\Run: [PE2CKFNT SE] C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\ChkFont.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DC1300 Monitor] C:\Program Files\DC1300\DCMnt1_0\DC1300mi.exe
O4 - HKLM\..\Run: [adiras] adiras.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [eBayToolbar] C:\Program Files\eBay\eBay Toolbar2\eBayTBDaemon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m
O4 - Startup: Joint Operations Typhoon Rising Registration.lnk = C:\Documents and Settings\Comet Stockport\Local Settings\Temp\{C9C63CAD-0DF7-4642-A942-15A0CABED7A7}\{0325F1C1-883A-41AB-8981-B27359ABDFAF}\NOVG.EXE
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Photo Express Calendar Checker SE.lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 2 SE\CalCheck.exe
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) -
http://gamingzone.ub...s/GSManager.cabO16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip....pGameLoader.dllO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {33E54F7F-561C-49E6-929B-D7E76D3AFEB1} (Pool Control) -
http://www.worldwinn...5/pool/pool.cabO16 - DPF: {3FE16C08-D6A7-4133-84FC-D5BFB4F7D886} (WebGameLoader Class) -
http://www.miniclip....bGameLoader.cabO16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://spaces.msn.co...ad/MsnPUpld.cabO16 - DPF: {556DDE35-E955-11D0-A707-000000521957} -
http://www.xblock.co...clean_micro.exeO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1129292599031O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai...all/xscan53.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4D