Lol I guess your right. Although I dont think I went to any that might have given it to me. hmmm..
Incident Status Location
Adware:adware/searchaid Not disinfected Windows Registry
Possible Virus. Not disinfected C:\WINDOWS\SYSTEM\BTIEIN.DLL
Dialer:Dialer.XH Not disinfected E:\!KillBox\99930182.exe
Spyware:Spyware/WinWhatWhere Not disinfected E:\!KillBox\aa81232.exe
Adware:Adware/WinTools Not disinfected E:\!KillBox\btlink.dll
Virus:Trj/Downloader.MO Not disinfected E:\!KillBox\default.inf
Spyware:Spyware/BetterInet Not disinfected E:\!KillBox\flash.inf
Adware:Adware/SideStep Not disinfected E:\!KillBox\httppost.exe
Adware:Adware/eZula Not disinfected E:\!KillBox\iMeshV3.exe
Virus:Trj/Autodelete.A Not disinfected E:\!KillBox\ipjf.bat
Virus:Bck/IRCFlood.I Not disinfected E:\!KillBox\msimp.reg
Adware:Adware/SAHAgent Not disinfected E:\!KillBox\payload.inf
Adware:Adware/SideStep Not disinfected E:\!KillBox\SbCIe026.dll
Hacktool:HackTool/SRunner.A Not disinfected E:\!KillBox\service.exe
Adware:Adware/SideStep Not disinfected E:\!KillBox\SideStep026.exe
Virus:Trj/Runet.A Not disinfected E:\!KillBox\system.css
Spyware:Spyware/BetterInet Not disinfected E:\!KillBox\turbo.inf
Dialer:Dialer.Gen Not disinfected E:\Documents and Settings\tc\My Documents\s2k.serials2k7.1.zip[s2k.hacking.exe]
Virus:Trj/Multidropper.ABN Not disinfected E:\limewire\Propellerheads Recycle v2.1 Incl Keygen-H2o.zip[Setup.exe]
Virus:Eicar.Mod Not disinfected E:\Program Files\PestPatrol\Help.chm[HowCanITestDetection.html]
Spyware:Spyware/Altnet Not disinfected E:\Program Files\PestPatrol\Quarantine\20040613131526358.zip[topsearch.dll]
Spyware:Spyware/Altnet Not disinfected E:\Program Files\PestPatrol\Quarantine\20040613131526358.zip[Points Manager.exe]
Adware:Adware/SearchAid Not disinfected E:\Program Files\PestPatrol\Quarantine\20040613131526358.zip[submithook.dll]
Adware:Adware/P2PNetworking Not disinfected E:\Program Files\PestPatrol\Quarantine\20050715134544917.zip[p2p networking.exe]
Adware:Adware/P2PNetworking Not disinfected E:\Program Files\PestPatrol\Quarantine\20050715134544917.zip[marshal.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp.cab[mshp.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp0.cab[mshp.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp1.cab[mshp.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp2.cab[mshp.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp3.cab[mshp.dll]
Adware:Adware/SearchWhat Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\mshp4.cab[mshp.dll]
Adware:Adware/KeenValue Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\PerfectNavUninstall.cab[PerfectNavUninstall.exe]
Adware:Adware/SearchAid Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\submithook.cab[submithook.dll]
Adware:Adware/SearchAid Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\submithook0.cab[submithook.dll]
Adware:Adware/SearchAid Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\submithook1.cab[submithook.dll]
Adware:Adware/SearchAid Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\submithook2.cab[submithook.dll]
Adware:Adware/SearchAid Not disinfected E:\Program Files\SpyFerret by OnlinePCfix\Archives\submithook3.cab[submithook.dll]
Virus:Bck/IRCFlood.M Not disinfected E:\WINDOWS\system32\~uninstal.exe
Virus:Bck/IRCFlood.I Not disinfected E:\WINDOWS\system32\~uninstal.exe[ms32.dll]
Virus:Bck/IRCFlood.I Not disinfected E:\WINDOWS\system32\~uninstal.exe[msimp.reg]
Virus:Bck/mIRCBased.F Not disinfected E:\WINDOWS\system32\~uninstal.exe[msthost.exe]
Virus:W32/Randon.CO.worm Not disinfected E:\WINDOWS\system32\~uninstal.exe[qos.dll]
Hacktool:HackTool/SRunner.A Not disinfected E:\WINDOWS\system32\~uninstal.exe[service.exe]
Virus:Bck/IRCFlood.I Not disinfected E:\WINDOWS\system32\~uninstal.exe[setsys.exe]
Virus:Bck/IRCFlood.M Not disinfected E:\WINDOWS\system32\~uninstal.exe[setuphlp.cmd]
Logfile of HijackThis v1.99.1
Scan saved at 10:45:40 PM, on 12/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\Explorer.EXE
E:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
E:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
E:\Program Files\ewido\security suite\ewidoctrl.exe
E:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
E:\WINDOWS\System32\nvsvc32.exe
E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
E:\PROGRA~1\PESTPA~1\PPControl.exe
E:\WINDOWS\wanmpsvc.exe
E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
E:\Program Files\iTunes\iTunesHelper.exe
E:\WINDOWS\system32\RUNDLL32.EXE
E:\Program Files\Bonjour\mDNSResponder.exe
E:\WINDOWS\system32\devldr32.exe
E:\Program Files\iPod\bin\iPodService.exe
E:\WINDOWS\system32\wscntfy.exe
E:\Program Files\Internet Explorer\IEXPLORE.EXE
E:\Documents and Settings\tc\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: ATLDistrib Object - {3FE36807-69ED-45D1-B9BE-85C0E3F75B6A} - E:\WINDOWS\system32\ddaxy.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [vptray] E:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PPMemCheck] E:\PROGRA~1\PESTPA~1\PPMemCheck.exe
O4 - HKLM\..\Run: [PestPatrol Control Center] E:\PROGRA~1\PESTPA~1\PPControl.exe
O4 - HKLM\..\Run: [CookiePatrol] E:\PROGRA~1\PESTPA~1\CookiePatrol.exe
O4 - HKLM\..\Run: [iTunesHelper] "E:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SpyFerret] E:\Program Files\SpyFerret by OnlinePCfix\SFerret.exe /updaterun
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\WINDOWS\System32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: e:\program files\bonjour\mdnsnsp.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1120225742533O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO20 - Winlogon Notify: ddaxy - E:\WINDOWS\system32\ddaxy.dll
O20 - Winlogon Notify: NavLogon - E:\WINDOWS\System32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - E:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - E:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: DefWatch - Symantec Corporation - E:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - E:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - E:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - E:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - E:\WINDOWS\wanmpsvc.exe
VundoFix V2.15 by Atri
--------------------------------------------------------------------------------------
Listing files contained in the vundofix folder.
--------------------------------------------------------------------------------------
killvundo.bat
process.exe
ReadMe.txt
vundo.reg
vundofix.txt
--------------------------------------------------------------------------------------
Filepaths entered
--------------------------------------------------------------------------------------
The filepath entered was C:\WINDOWS\system32\ddaxy.dll
The second filepath entered was C:\WINDOWS\system32\yxadd.*
--------------------------------------------------------------------------------------
Log from Process
--------------------------------------------------------------------------------------
Killing PID 184 'smss.exe'
Killing PID 816 'explorer.exe'
Killing PID 264 'winlogon.exe'
--------------------------------------------------------------------------------------
C:\WINDOWS\system32\ddaxy.dll Deleted sucessfully.
C:\WINDOWS\system32\yxadd.* Deleted sucessfully.
Fixing Registry
--------------------------------------------------------------------------------------