Looks like we got some work to do. Note that there was no DealHelper in programs, but did notice a D-helper Web Driver in the add/remove programs. Did not remove it. Couple others not present, and MyQuickSearch would not delete-returned stop error message, could not find specified module- one that we removed in prior HJT fix process, I believe. Also, with every shutdown, get a wait while program closes box-SAMPLE which takes a few seconds longer to close (as an FYI). Here we go with logs.
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Monday, November 07, 2005 20:29:36
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 8/11/2005
Kaspersky Anti-Virus database records: 158740
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
Scan Statistics:
Total number of scanned objects: 58675
Number of viruses found: 53
Number of infected objects: 146
Number of suspicious objects: 6
Duration of the scan process: 4551 sec
Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc.zip/istsvc.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc1.zip/istsvc.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechISTsvc1.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch.zip/istsvc.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ISearchTechSlotch.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\Andrew\Local Settings\Temp\installer.exe Infected: Trojan-Dropper.Win32.PurityScan.q
C:\Documents and Settings\Andrew\mt-uninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\Documents and Settings\Andrew\mt-uninstaller.exe Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\Program Files\ProSiteFinder\prositefinder.exe Infected: not-a-virus:AdWare.Win32.ClearSearch.aa
C:\RECYCLER\S-1-5-21-3028300340-1542900787-4098053600-500\Dc1.exe Infected: Trojan-Dropper.Win32.Agent.mm
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP100\A0005578.exe Infected: Trojan-Downloader.Win32.IstBar.gen
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP100\A0005579.exe Infected: Trojan-Downloader.Win32.IstBar.ij
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP101\A0005588.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP101\A0005673.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP102\A0005690.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP102\A0005705.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP102\A0005745.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP102\A0005762.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP103\A0005778.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP104\A0005823.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP106\A0005879.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP107\A0005882.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP108\A0005918.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP109\A0005944.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP109\A0005972.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP110\A0006004.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP111\A0006034.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP112\A0006064.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP113\A0006097.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP114\A0006124.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP116\A0006150.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP118\A0006212.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP119\A0006236.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP119\A0006266.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP121\A0006284.dll Infected: not-a-virus:AdWare.Win32.DealHelper.ab
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP122\A0006306.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP122\A0006310.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP122\A0006310.exe Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP122\A0006363.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP123\A0006376.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP124\A0006420.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP125\A0006471.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP126\A0006492.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP127\A0006517.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP129\A0006544.dll Infected: not-a-virus:AdWare.Win32.Sahat.ad
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP129\A0006545.exe Infected: not-a-virus:AdWare.Win32.Sahat.ah
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP129\A0006548.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP130\A0006589.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP130\A0006637.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP131\A0006653.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP132\A0006657.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP133\A0006684.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP134\A0006710.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP135\A0006729.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP137\A0006748.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP138\A0006752.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP139\A0006770.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP140\A0006795.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP141\A0006966.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP142\A0006987.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP143\A0007003.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP144\A0007024.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP144\A0007043.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP145\A0007055.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP145\A0007073.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP146\A0007075.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP146\A0007092.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP147\A0007110.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP148\A0007133.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP148\A0007149.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP149\A0008154.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP150\A0008177.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP151\A0008184.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP152\A0008211.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP154\A0008233.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP155\A0008240.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP156\A0008260.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP157\A0008281.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP158\A0008289.exe Infected: Trojan-Downloader.Win32.Agent.ro
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP158\A0008302.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP159\A0008323.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP159\A0009041.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP159\A0009041.exe Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP160\A0009050.exe Infected: not-a-virus:AdWare.Win32.SurfAccuracy.c
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP160\A0009052.exe Infected: not-a-virus:AdWare.Win32.SurfAccuracy.d
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP161\A0009079.exe Infected: not-a-virus:AdWare.Win32.WinAD.bf
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP161\A0009082.exe Infected: Trojan.Win32.Small.cy
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP161\A0009084.exe Infected: not-a-virus:AdWare.Win32.DealHelper.ac
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP161\A0009085.exe Infected: not-a-virus:AdWare.Win32.Sahat.ai
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP94\A0005140.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP95\A0005230.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP96\A0005244.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP96\A0005257.exe Infected: not-a-virus:AdWare.Win32.180Solutions
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP96\A0005258.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005357.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005486.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005516.exe Infected: not-a-virus:AdWare.Win32.WebRebates.b
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005517.exe Infected: not-a-virus:AdWare.Win32.HelpExpress
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005518.exe Infected: not-a-virus:AdWare.Win32.WebRebates.b
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005520.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.j
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005521.dll Infected: not-a-virus:AdWare.Win32.BargainBuddy.j
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005522.dll Infected: not-a-virus:AdWare.Win32.BargainBuddy.j
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005523.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005524.exe Infected: Trojan-Downloader.Win32.Dyfuca.dp
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005525.exe Infected: Trojan-Downloader.Win32.Dyfuca.de
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005526.exe Infected: Trojan-Downloader.Win32.Dyfuca.de
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005527.dll Infected: not-a-virus:AdWare.Win32.180Solutions.j
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP98\A0005529.exe Infected: not-a-virus:AdWare.Win32.180Solutions.g
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005535.exe Infected: Trojan-Downloader.Win32.Apropo.g
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005538.dll Infected: Trojan-Downloader.Win32.Dyfuca.gen
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005539.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005540.exe Infected: Trojan.Win32.Small.cy
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005541.dll Infected: not-a-virus:AdWare.Win32.BargainBuddy.n
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005542.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005544.exe Infected: not-a-virus:AdWare.Win32.PowerScan.d
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005546.dll Infected: not-a-virus:AdWare.Win32.SideFind
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005547.dll Infected: not-a-virus:AdWare.Win32.SideFind
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005548.exe Infected: Trojan-Downloader.Win32.IstBar.jm
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005550.dll Infected: Trojan-Downloader.Win32.IstBar.ms
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005551.dll Infected: not-a-virus:AdWare.Win32.DealHelper.ab
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005552.exe Infected: not-a-virus:AdWare.Win32.WebRebates.k
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005553.exe Infected: not-a-virus:AdWare.Win32.WebRebates.k
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005554.exe Infected: not-a-virus:AdWare.Win32.WebRebates.o
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005555.dll Infected: not-a-virus:AdWare.Win32.WebRebates.n
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005556.exe Infected: not-a-virus:AdWare.Win32.WebRebates.n
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005562.exe Infected: not-a-virus:AdWare.Win32.BargainBuddy.q
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005564.exe Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005565.dll Infected: Trojan-Downloader.Win32.Apropo.ag
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005566.dll Infected: Trojan.Win32.Crypt.t
C:\System Volume Information\_restore{5EEA947E-90E9-4013-91A6-F28EFECABD28}\RP99\A0005567.exe Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll Infected: not-a-virus:AdWare.Win32.Gator.1019
C:\WINDOWS\Downloaded Program Files\DS3.dll Infected: Trojan-Downloader.Win32.Lookme.a
C:\WINDOWS\extract.exe/systb.dll Infected: not-a-virus:AdWare.Win32.ImiBar.c
C:\WINDOWS\extract.exe/wdskctl.exe Infected: not-a-virus:AdWare.Win32.ShopNav.g
C:\WINDOWS\extract.exe Infected: not-a-virus:AdWare.Win32.ShopNav.g
C:\WINDOWS\iconz3.exe Infected: not-a-virus:AdWare.Win32.Zestyfind
C:\WINDOWS\msbbi.exe/msbb.exe Infected: not-a-virus:AdWare.Win32.180Solutions
C:\WINDOWS\msbbi.exe Infected: not-a-virus:AdWare.Win32.180Solutions
C:\WINDOWS\mt-uninstaller.exe/data0002 Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\WINDOWS\mt-uninstaller.exe Infected: not-a-virus:AdWare.Win32.PurityScan.u
C:\WINDOWS\system\UpdInstall.exe Infected: not-a-virus:AdWare.Win32.Look2Me
C:\WINDOWS\system32\coreak.dll Infected: not-a-virus:AdWare.Win32.Coreak
C:\WINDOWS\system32\Cwwirs.exe Infected: not-a-virus:AdWare.Win32.DealHelper.ad
C:\WINDOWS\system32\dun.exe Infected: not-a-virus:AdWare.Win32.DealHelper.x
C:\WINDOWS\system32\f504an59.ini Infected: not-a-virus:AdWare.Win32.Sahat.ao
C:\WINDOWS\system32\ll90ks5q.exe Infected: not-a-virus:AdWare.Win32.Sahat.f
C:\WINDOWS\system32\lspak.dll Infected: Trojan-Downloader.Win32.Agent.br
C:\WINDOWS\system32\psnrunas.dll Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\system32\rulesak.dll Infected: Trojan-Downloader.Win32.Agent.bt
C:\WINDOWS\system32\updak.dll Infected: Trojan-Downloader.Win32.Agent.br
C:\WINDOWS\wsem303.dll Infected: Trojan-Downloader.Win32.Dyfuca.dt
Scan process completed.
>>>>>>>>>>>>>>>>>>>
HiJackThis Log
Logfile of HijackThis v1.99.1
Scan saved at 8:30:45 PM, on 11/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\system32\Zfgopl.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3SWK.EXE
C:\PROGRA~1\SECRET~1\run.exe
C:\Program Files\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.mymiami.muohio.edu/O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [PRONoMgr.exe] c:\Program Files\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [ZoneEdit] C:\6612.exe
O4 - HKLM\..\Run: [secure] C:\WINDOWS\system32\Zfgopl.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SecretSmileys] C:\PROGRA~1\SECRET~1\ss.exe
O4 - Global Startup: Canon PC1200 iC D700 Status Window.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPM3LAK.EXE
O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.muohio.edu
O15 - Trusted Zone:
http://download.windowsupdate.comO16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - Winlogon Notify: Sebring - c:\WINDOWS\System32\LgNotify.dll
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\Ivp\Swupdate\swupdtmr.exe
Much thanks are in order, as this looks like a head ache! I do have newer copy of NAV-would uninstall of McAfee and installatioin of NAV really accomplish anything? Thank you. Middie042