Hello you good people..
=======================PANDA SCAN FAILURE======================
Panda scan: Could not get it to run.
Case 1: when I clicked 'Scan your PC' button, it launched a window which said Firefox browser (my default browser) was not supported.
Case 2: when I made IE 6.0 my default browser and visited the Panda site and clicked 'Scan your PC' button, it launched nothing. Did nothing.
Case 3: I shutdown my Sysgate firewall thinking it might be blocking something and went to Panda and clicked 'Scan your PC' button, but still it launched nothing. Did nothing.
Case 4: Rebooted and redid case 3 but still nothing happened when I clicked the 'Scan your PC' button.
Every step preceding the Panda step went smoothly as per your excellent instructions. Here are all the logs, except the Panda scan.
=======================HIJACK THIS LOG======================
Logfile of HijackThis v1.99.1
Scan saved at 9:31:54 PM, on 11/17/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INSTANCEMIXED\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\inetsrv\inetinfo.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINNT\system32\atiptaxx.exe
C:\WINNT\system32\desk95.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
C:\Program Files\DynDNS Updater\DynDNS.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Reader7\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [zzzHPSETUP] D:\Setup.exe
O4 - HKLM\..\Run: [CamMonitor] C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [HydraVisionDesktopManager] desk95.exe
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [HGTXPEI] C:\WINNT\system32\UninstallXP.exe 1
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKCU\..\Run: [ATIRmtWndr] C:\Program Files\ATI Multimedia\RemCtrl\ATIX10.exe
O4 - HKCU\..\Run: [DynDNS Updater] "C:\Program Files\DynDNS Updater\DynDNS.exe"
O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader7\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{217C6BFF-060B-4D77-9D14-C61D46A4835C}: NameServer = 209.87.239.20,204.187.144.34
O17 - HKLM\System\CS2\Services\Tcpip\..\{217C6BFF-060B-4D77-9D14-C61D46A4835C}: NameServer = 209.87.239.20,204.187.144.34
O17 - HKLM\System\CS3\Services\Tcpip\..\{217C6BFF-060B-4D77-9D14-C61D46A4835C}: NameServer = 209.87.239.20,204.187.144.34
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAM FILES\AVPERSONAL\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
O23 - Service: X10 Device Network Service (x10nets) - Unknown owner - C:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)
=======================FINDFILES TXT======================
Volume in drive C is Local Disk
Volume Serial Number is BC31-D58C
Directory of C:\WINNT\system32
09/29/2005 08:36a 401,408 r?gedit.exe
1 File(s) 401,408 bytes
Directory of C:\Documents and Settings\Administrator\Desktop
=======================SMITFILES LOG======================
smitRem © log file
version 2.7
by noahdfear
Microsoft Windows 2000 [Version 5.00.2195]
The current date is: Thu 11/17/2005
The current time is: 19:04:44.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
checking for ShudderLTD key
ShudderLTD key not present!
checking for PSGuard.com key
PSGuard.com key not present!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Existing Pre-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
PSGuard.com
Install.dat
~~~ Favorites ~~~
~~~ system32 folder ~~~
wp.bmp
logfiles
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Remaining Post-run Files
~~~ Program Files ~~~
~~~ Shortcuts ~~~
~~~ Favorites ~~~
~~~ system32 folder ~~~
~~~ Icons in System32 ~~~
~~~ Windows directory ~~~
~~~ Drive root ~~~
~~~ Miscellaneous Files/folders ~~~
~~~ Wininet.dll ~~~
CLEAN!
=======================EWIDO SCAN REPORT======================
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 8:39:00 PM, 11/17/2005
+ Report-Checksum: 31A4B7E
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\7pk4k6bd.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.15:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.16:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.17:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.25:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.27:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.32:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\NICK\ASPNET\Application Data\Mozilla\Firefox\Profiles\9ybvq3bp.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Nick\TempNick\nerocrack\Keygen.exe -> TrojanDropper.Delf.gi : Cleaned with backup
::Report End