This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Information.exe

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

When I run Lavasoft Ad-Aware SE, a window pops us saying there is a trojan here: C:\WINDOWS\TEMP\AAWTMP\C159915\INFORMATION.EXE. Here is the Ad-Aware log: what can I do? Thanks Ad-Aware SE Build 1.04 Logfile Created on:venerdì 10 settembre 2004 18.25.43 Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R7 06.09.2004 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Alexa(TAC index:5):1 total references MRU List(TAC index:0):34 total references Tracking Cookie(TAC index:3):95 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 10-09-2004 18.25.43 - Scan started. (Full System Scan) MRU List Object Recognized! Location: : .DEFAULT\software\nico mak computing\winzip\filemenu Description : winzip recently used archives MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\applets\wordpad\recent file list Description : list of recent files opened using wordpad MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\applets\paint\recent file list Description : list of files recently opened using microsoft paint MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\runmru Description : mru list for items opened in start | run MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\office\9.0\excel\recent files Description : list of recent files used by microsoft excel MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\player\recentfilelist Description : list of recently used files in microsoft windows media player MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\internet explorer\main Description : last save directory used in microsoft internet explorer MRU List Object Recognized! Location: : .DEFAULT\software\realnetworks\realplayer\6.0\preferences Description : list of recent skins in realplayer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\internet explorer Description : last download directory used in microsoft internet explorer MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : .DEFAULT\software\corel\user assistant\8\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\player\settings Description : last save as directory used in jasc paint shop pro MRU List Object Recognized! Location: : .DEFAULT\software\corel\user assistant\8\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\internet explorer\typedurls Description : list of recently entered addresses in microsoft internet explorer MRU List Object Recognized! Location: : .DEFAULT\software\adobe\acrobat reader\6.0\avgeneral\crecentfiles Description : list of recently used files in adobe reader MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\player\settings Description : last open directory used in jasc paint shop pro MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\musicmatch Description : download location of the musicmatch installer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\preferences Description : last playlist index loaded in microsoft windows media player MRU List Object Recognized! Location: : .DEFAULT\software\realnetworks\realplayer\6.0\preferences Description : list of recent clips in realplayer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows\currentversion\applets\regedit Description : last key accessed using the microsoft registry editor MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\directinput\mostrecentapplication Description : most recent application to use microsoft directinput MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! Location: : .DEFAULT\software\realnetworks\realplayer\6.0\preferences Description : last login time in realplayer MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\player\recenturllist Description : list of recently used web addresses in microsoft windows media player MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\mediaplayer\medialibraryui Description : last selected node in the microsoft windows media player media library MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general Description : windows media sdk Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [KERNEL32.DLL] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4279175791 Threads : 4 Priority : High FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Sistema operativo Microsoft® Windows® Millennium CompanyName : Microsoft Corporation FileDescription : Componente di base del kernel di Win32 InternalName : KERNEL32 LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : KERNEL32.DLL #:2 [MSGSRV32.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294921423 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Sistema operativo Microsoft® Windows® Millennium CompanyName : Microsoft Corporation FileDescription : Server messaggi VxD a 32 bit di Windows InternalName : MSGSRV32 LegalCopyright : Copyright © Microsoft Corp. 1992-1998 OriginalFilename : MSGSRV32.EXE #:3 [SPOOL32.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294919415 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Spooler Sub System Process InternalName : spool32 LegalCopyright : Copyright © Microsoft Corp. 1994 - 1998 OriginalFilename : spool32.exe #:4 [MPREXE.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294945871 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : WIN32 Network Interface Service Process InternalName : MPREXE LegalCopyright : Copyright © Microsoft Corp. 1993-2000 OriginalFilename : MPREXE.EXE #:5 [MSTASK.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294836283 Threads : 2 Priority : Normal FileVersion : 4.71.2721.1 ProductVersion : 4.71.2721.1 ProductName : Utilità di pianificazione per Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Modulo di gestione dell'Utilità di pianificazione InternalName : TaskScheduler LegalCopyright : Copyright © Microsoft Corp. 2000 OriginalFilename : mstask.exe #:6 [STIMON.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294864579 Threads : 5 Priority : Normal FileVersion : 4.90.3000.1 ProductVersion : 4.90.3000.1 ProductName : Sistema operativo Microsoft® Windows® Millennium CompanyName : Microsoft Corporation FileDescription : Monitor per periferiche di acquisizione immagini InternalName : STIMON LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : STIMON.EXE #:7 [AVGSERV9.EXE] FilePath : C:\PROGRAMMI\GRISOFT\AVG6\ ProcessID : 4294861863 Threads : 2 Priority : Normal FileVersion : 6.0.1.374 ProductVersion : 6.0.1.374 ProductName : AVG6 CompanyName : GRISOFT, s.r.o FileDescription : AvgServ - displays notification message InternalName : AvgServ LegalCopyright : Copyright © GRISOFT, s.r.o. 1998-2002 OriginalFilename : AvgServ #:8 [OUTPOST.EXE] FilePath : C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\ ProcessID : 4294855735 Threads : 1 Priority : Normal FileVersion : 1.0.242 ProductVersion : 1.0 ProductName : Outpost Firewall CompanyName : Agnitum FileDescription : Outpost Firewall main module InternalName : Outpost Firewall LegalCopyright : © Agnitum, 1999-2001 OriginalFilename : outpost.exe #:9 [mmtask.tsk] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294796587 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft Windows CompanyName : Microsoft Corporation FileDescription : Multimedia background task support module InternalName : mmtask.tsk LegalCopyright : Copyright © Microsoft Corp. 1991-2000 OriginalFilename : mmtask.tsk #:10 [EXPLORER.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294788651 Threads : 19 Priority : Normal FileVersion : 5.50.4134.100 ProductVersion : 5.50.4134.100 ProductName : Sistema Operativo Microsoft® Windows ® 2000 CompanyName : Microsoft Corporation FileDescription : Esplora risorse InternalName : explorer LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : EXPLORER.EXE #:11 [STMGR.EXE] FilePath : C:\WINDOWS\SYSTEM\RESTORE\ ProcessID : 4294789583 Threads : 6 Priority : Normal FileVersion : 4.90.0.2533 ProductVersion : 4.90.0.2533 ProductName : Microsoft ® Prevenzione e risoluzione dei problemi CompanyName : Microsoft Corporation FileDescription : Microsoft ® PC State Manager InternalName : StateMgr.exe LegalCopyright : Copyright © Microsoft Corp. 1981-2000 OriginalFilename : StateMgr.exe #:12 [TASKMON.EXE] FilePath : C:\WINDOWS\ ProcessID : 4294819923 Threads : 1 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : Task Monitor InternalName : TaskMon LegalCopyright : Copyright © Microsoft Corp. 1998 OriginalFilename : TASKMON.EXE #:13 [SYSTRAY.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294719467 Threads : 2 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Sistema operativo Microsoft® Windows® Millennium CompanyName : Microsoft Corporation FileDescription : Applicazione System Tray InternalName : SYSTRAY LegalCopyright : Copyright © Microsoft Corp. 1993-2000 OriginalFilename : SYSTRAY.EXE #:14 [AVGCC32.EXE] FilePath : C:\PROGRAMMI\GRISOFT\AVG6\ ProcessID : 4294753655 Threads : 1 Priority : Normal FileVersion : 6, 0, 0, 515 ProductVersion : 6, 0, 0, 0 ProductName : AVG Anti-Virus System CompanyName : GRISOFT s.r.o. FileDescription : AVG Control Center InternalName : AvgCC32 LegalCopyright : Copyright © 2003 GRISOFT s.r.o. OriginalFilename : AvgCC32.EXE #:15 [ICSMGR.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294769055 Threads : 11 Priority : Normal FileVersion : 4.90.3000 ProductVersion : 4.90.3000 ProductName : Sistema operativo Microsoft® Windows® Millennium CompanyName : Microsoft Corporation FileDescription : Gestione condivisione connessione Internet Microsoft InternalName : ICSMGR LegalCopyright : Copyright © Microsoft Corp. 1998-1999 OriginalFilename : ICSMGR.EXE #:16 [WMIEXE.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294766671 Threads : 3 Priority : Normal FileVersion : 4.90.2452.1 ProductVersion : 4.90.2452.1 ProductName : Microsoft® Windows® Millennium Operating System CompanyName : Microsoft Corporation FileDescription : WMI service exe housing InternalName : wmiexe LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : wmiexe.exe #:17 [DIRECTCD.EXE] FilePath : C:\PROGRAMMI\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\ ProcessID : 4294650219 Threads : 1 Priority : Normal FileVersion : 5.10 (115) ProductVersion : 5.10 (115) ProductName : DirectCD CompanyName : Roxio FileDescription : DirectCD Application InternalName : DirectCD LegalCopyright : Copyright © 2001, Roxio, Inc. OriginalFilename : Directcd.exe #:18 [TERMINATOR.EXE] FilePath : C:\PROGRAMMI\SPAM TERMINATOR\ ProcessID : 4294791603 Threads : 3 Priority : Normal FileVersion : 2.03.0151 ProductVersion : 2.03.0151 ProductName : Spam Terminator CompanyName : SertelNet FileDescription : Spam Terminator InternalName : Terminator LegalCopyright : ©2000-2003 SertelNet - Alex Palmese OriginalFilename : Terminator.exe #:19 [PSTORES.EXE] FilePath : C:\WINDOWS\SYSTEM\ ProcessID : 4294226155 Threads : 3 Priority : Normal FileVersion : 5.00.2133.2 ProductVersion : 5.00.2133.2 ProductName : Microsoft® Windows ® 2000 Operating System CompanyName : Microsoft Corporation FileDescription : Protected storage server InternalName : Protected storage server LegalCopyright : Copyright © Microsoft Corp. 1981-1999 OriginalFilename : Protected storage server #:20 [AD-AWARE.EXE] FilePath : C:\PROGRAMMI\LAVASOFT\AD-AWARE SE PERSONAL\ ProcessID : 4294198779 Threads : 2 Priority : Normal FileVersion : 6.2.0.200 ProductVersion : VI.Second Edition ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 34 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Alexa Object Recognized! Type : Regkey Data : Category : Data Miner Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\internet explorer\extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 35 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 35 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tripod.lycos[4].txt Category : Data Miner Comment : 09-09-2004 18.05.30 Value : Cookie:.@ads.tripod.lycos.it/ Expires : 10-09-2004 17.48.28 LastSync : 09-09-2004 18.05.30 UseCount : 0 Hits : 23 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@as1.falkag[3].txt Category : Data Miner Comment : 31-07-2004 16.24.34 Value : Cookie:.@as1.falkag.de/ Expires : 30-08-2004 16.09.30 LastSync : 31-07-2004 16.24.34 UseCount : 0 Hits : 29 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@kelkoo[4].txt Category : Data Miner Comment : 09-09-2004 17.54.16 Value : Cookie:.@kelkoo.it/ Expires : 09-09-2006 16.25.18 LastSync : 09-09-2004 17.54.16 UseCount : 0 Hits : 12 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@kelkoo[2].txt Category : Data Miner Comment : 09-09-2004 17.54.16 Value : Cookie:.@kelkoo.com/ Expires : 02-08-2006 22.59.00 LastSync : 09-09-2004 17.54.16 UseCount : 0 Hits : 9 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@statcounter[1].txt Category : Data Miner Comment : 10-08-2004 17.11.46 Value : Cookie:.@statcounter.com/ Expires : 09-08-2009 16.56.04 LastSync : 10-08-2004 17.11.46 UseCount : 0 Hits : 22 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fortunecity[1].txt Category : Data Miner Comment : 30-07-2004 14.07.36 Value : Cookie:.@fortunecity.com/ Expires : 01-01-2011 1.59.58 LastSync : 30-07-2004 14.07.36 UseCount : 0 Hits : 9 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@versiontracker[1].txt Category : Data Miner Comment : 31-05-2004 21.53.50 Value : Cookie:.@versiontracker.com/ Expires : 31-05-2006 14.41.24 LastSync : 31-05-2004 21.53.50 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@maxserving[3].txt Category : Data Miner Comment : 15-07-2004 19.07.26 Value : Cookie:.@maxserving.com/ Expires : 13-07-2014 18.53.02 LastSync : 15-07-2004 19.07.26 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@bravenet[2].txt Category : Data Miner Comment : 07-09-2004 11.19.40 Value : Cookie:.@bravenet.com/ Expires : 05-09-2014 11.03.22 LastSync : 07-09-2004 11.19.40 UseCount : 0 Hits : 55 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@prv[1].txt Category : Data Miner Comment : 04-07-2004 0.29.58 Value : Cookie:.@prv.pl/ Expires : 04-07-2004 1.16.08 LastSync : 04-07-2004 0.29.58 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@tripod[2].txt Category : Data Miner Comment : 23-05-2004 9.19.50 Value : Cookie:.@tripod.com/ Expires : 23-05-2005 9.08.02 LastSync : 23-05-2004 9.19.50 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@webads[1].txt Category : Data Miner Comment : 10-07-2004 13.07.14 Value : Cookie:.@webads.nl/ Expires : 01-03-2012 1.59.58 LastSync : 10-07-2004 13.07.14 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@stat.onestat[2].txt Category : Data Miner Comment : 04-06-2004 22.05.56 Value : Cookie:.@stat.onestat.com/ Expires : 04-06-2014 2.00.00 LastSync : 04-06-2004 22.05.56 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@hc2.humanclick[3].txt Category : Data Miner Comment : 27-06-2004 1.10.48 Value : Cookie:.@hc2.humanclick.com/ Expires : 27-06-2005 0.57.18 LastSync : 27-06-2004 1.10.48 UseCount : 0 Hits : 2 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@realmedia[2].txt Category : Data Miner Comment : 23-05-2004 9.09.04 Value : Cookie:.@realmedia.com/ Expires : 01-01-2011 1.59.58 LastSync : 23-05-2004 9.09.04 UseCount : 0 Hits : 3 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@server.iad.liveperson[2].txt Category : Data Miner Comment : 09-07-2004 13.45.06 Value : Cookie:.@server.iad.liveperson.net/ Expires : 27-06-2005 13.19.04 LastSync : 09-07-2004 13.45.06 UseCount : 0 Hits : 14 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@cgi-bin[1].txt Category : Data Miner Comment : 23-07-2004 16.24.24 Value : Cookie:[removed]/cgi-bin/ Expires : 21-01-2005 16.09.34 LastSync : 23-07-2004 16.24.24 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fortunecity[6].txt Category : Data Miner Comment : 28-08-2004 12.47.16 Value : Cookie:.@fortunecity.it/ Expires : 28-08-2005 12.30.00 LastSync : 28-08-2004 12.47.16 UseCount : 0 Hits : 8 Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@statcounter[1].txt Category : Data Miner Comment : 23-07-2004 16.25.42 Value : Cookie:[removed]/ Expires : 22-07-2009 16.10.48 LastSync : 23-07-2004 16.25.42 UseCount : 0 Hits : 1 Tracking Cookie Object Recognized! Type : IECache Entry Data : .@zedo[4].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@zedo[4].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@dbbsrv[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@dbbsrv[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@questionmarket[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@questionmarket[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@search.netster[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@search.netster[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@estat[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@estat[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@zedo[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@zedo[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@www.angelfire[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@www.angelfire[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@at.netster[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@at.netster[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ru4[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ru4[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ad-logics[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ad-logics[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tripod.lycos[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.tripod.lycos[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@euniverseads[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@euniverseads[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@spylog[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@spylog[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@hit1.vioclicks[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@hit1.vioclicks[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@hypercount[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@hypercount[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@paycounter[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@paycounter[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@weborama[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@weborama[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@tradedoubler[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@tradedoubler[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@trafficmp[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@trafficmp[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.multimania.lycos[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.multimania.lycos[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@xxxcounter[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@xxxcounter[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@www.maximumcash[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@www.maximumcash[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@zedo[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@zedo[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fl01.ct2.comclick[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@fl01.ct2.comclick[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@hotlog[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@hotlog[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@accumail[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@accumail[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@www.sex-in-www[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@www.sex-in-www[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@overture[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@overture[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@oasis.adserver.m2kcore[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@oasis.adserver.m2kcore[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@adserver.hispavista[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@adserver.hispavista[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tripod.lycos[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.tripod.lycos[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tucows[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.tucows[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.valuead[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.valuead[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@vad.mainentrypoint[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@vad.mainentrypoint[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.specificpop[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.specificpop[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@bluestreak[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@bluestreak[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@addynamix[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@addynamix[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fortunecity[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@fortunecity[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@server.iad.liveperson[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@server.iad.liveperson[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@tripod[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@tripod[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@xxxcounter[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@xxxcounter[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@2o7[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@2o7[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@questionmarket[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@questionmarket[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@www.angelfire[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@www.angelfire[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@spylog[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@spylog[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@weborama[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@weborama[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tucows[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.tucows[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@trafficmp[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@trafficmp[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fortunecity[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@fortunecity[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@bravenet[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@bravenet[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@versiontracker[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@versiontracker[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@tribalfusion[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@tribalfusion[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@xxxcounter[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@xxxcounter[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@pointroll[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@pointroll[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@rccl.bridgetrack[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@rccl.bridgetrack[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@realmedia[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@realmedia[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@z1.adserver[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@z1.adserver[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@c.porngraph[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@c.porngraph[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@trafficmp[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@trafficmp[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@maxserving[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@maxserving[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@ads.tucows[4].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@ads.tucows[4].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@2o7[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@2o7[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@etype.adbureau[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@etype.adbureau[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@fortunecity[4].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@fortunecity[4].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@trafic[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@trafic[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@weborama[4].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@weborama[4].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@questionmarket[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@questionmarket[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@adserver.geizkragen[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@adserver.geizkragen[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@a.as-eu.falkag[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@a.as-eu.falkag[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@edge.ru4[2].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@edge.ru4[2].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@hc2.humanclick[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@hc2.humanclick[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@kelkoo[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@kelkoo[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@kelkoo[3].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@kelkoo[3].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : .@as1.falkag[1].txt Category : Data Miner Comment : Value : C:\WINDOWS\Cookies\.@as1.falkag[1].txt Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 93 Objects found so far: 128 Deep scanning and examining files (c:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@cgi-bin[1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@cgi-bin[1].txt Tracking Cookie Object Recognized! Type : IECache Entry Data : anyuser@statcounter[1].txt Category : Data Miner Comment : Value : c:\WINDOWS\Cookies\anyuser@statcounter[1].txt Disk Scan Result for c:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 130 Deep scanning and examining files (d:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for d:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 130 Performing conditional scans… »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 130 18.34.58 Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00.09.15.840 Objects scanned:91216 Objects identified:96 Objects ignored:0 New critical objects:96
Here's how to post a Hijack This log

Download "HijackThis" here
When downloading, choose "save to disk" and NOT open!

Now create a new folder for it, C:\Hijackthis, for example.
After unzipping the file. to C:\Hijack This, you'll end up with the file itself, which is Hijackthis.exe, and that's the one you'll need to doubleclick.'

When the program launches, hit the "Scan" button
When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, and save the log anywhere you like.

Now if you doubleclick the log file.Go to Edit > Select all, then to Edit > copy.
Now you've copied the entire text to the Windows Clipboard (this happens behind your back.)

Next, go back to this forum thread, and click "Add Reply".
In an empty area click your RIGHT mouse button, and choose 'Paste' from the context menu.
There's your Hijack This log.
thanks for your patience!


Logfile of HijackThis v1.98.2
Scan saved at 17.25.30, on 11/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\OUTPOST.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMI\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://security.kolla.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [SpamTerminator] C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.exe
O8 - Extra context menu item: Enqueue in Star Downloader - C:\PROGRAMMI\STAR DOWNLOADER\sdieenq.htm
O8 - Extra context menu item: &Download with DownloadPlus! - C:\PROGRAMMI\DOWNLOADPLUS\downloadplus.htm
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Reference 2001\EROProj.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
I don't see anything in the log. :D

Run Ad-aware again using these settings

Reconfigure Ad-Aware for Full Scan:

Launch the program, and click on the Gear at the top of the start screen.

Click the "Scanning" button.
Under Drives, Folders and Files, select "Scan within Archives".
Click "Click here to select Drives + folders" and select your installed hard drives.

Under Memory & Registry, select all options.
Click the "Advanced" button.
Under "Log-file detail level", select all options.
Click the "Tweaks" button.

Under "Scanning Engine", select the following:
"Unload recognized processes during scanning."
Under "Cleaning Engine", select the following:
"Let Windows remove files in use after reboot."
Click on 'Proceed' to save these Preferences.

Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT to allow it to finish.

Before removing check and see what it found?
While scanning with Ad-Aware (I was online), I got hit by 4 viruses that AVG can't get rid of.

Results of Complete Test, date and time 11/09/2004 18.53.35 :

Testing C:\ volume DISCO C serial 252C-16EA
C:\_RESTORE\TEMP\A0000598.CPY Virus identified I-Worm/Opas.G
C:\_RESTORE\TEMP\A0000599.CPY Virus identified I-Worm/Opas.B
C:\_RESTORE\TEMP\A0000600.CPY Virus identified Win32/Dupator
C:\_RESTORE\TEMP\A0000601.CPY Virus identified Win32/Dupator

Plus, trojan horse dialer 8.BA is still in my PC, even though Ad-Aware scanning is now clean (I followed your directions).

Here's HJT scan:

Logfile of HijackThis v1.98.2
Scan saved at 18.59.49, on 11/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\OUTPOST.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMI\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://security.kolla.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F1 - win.ini: run=c:\windows\alevir.exe,c:\windows\scrsvr.exe,c:\windows\marco!.scr
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [SpamTerminator] C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.exe
O8 - Extra context menu item: Enqueue in Star Downloader - C:\PROGRAMMI\STAR DOWNLOADER\sdieenq.htm
O8 - Extra context menu item: &Download with DownloadPlus! - C:\PROGRAMMI\DOWNLOADPLUS\downloadplus.htm
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Reference 2001\EROProj.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab

what can I do? thanks
FS4.CABA0000110.CPY WIN32 OPASERV.A
FS4.CABA0000111.CPY WIN32 OPASERV.G
FS4.CABA0000112.CPY WIN32 OPASERV.F
FS4.CABA0000113.CPY WIN95 DUPATOR.1503
FS4.CABA0000598.CPY WIN95 DUPATOR.1503
FS4.CABA0000599.CPY WIN32 OPASERV.B
FS4.CABA0000600.CPY WIN95 DUPATOR.1503
FS4.CABA0000601.CPY WIN95 DUPATOR.1503

These can't be fixed: they are in C.\_RESTORE\ARCHIVE

I couldn't run Panda ActiveScan, though: javascript:pp(1,2,63);

No trojans

here's HJT scan:



Logfile of HijackThis v1.98.2
Scan saved at 23.24.53, on 11/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\OUTPOST.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMI\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://security.kolla.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F1 - win.ini: run=c:\windows\alevir.exe,c:\windows\scrsvr.exe,c:\windows\marco!.scr
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [SpamTerminator] C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.exe
O8 - Extra context menu item: Enqueue in Star Downloader - C:\PROGRAMMI\STAR DOWNLOADER\sdieenq.htm
O8 - Extra context menu item: &Download with DownloadPlus! - C:\PROGRAMMI\DOWNLOADPLUS\downloadplus.htm
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Reference 2001\EROProj.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
One of the best features of Windows ME is the System Restore option, however if a virus infects a computer with this operating system the virus can be backed up in the System Restore folder. Therefore, clearing the restore points is necessary after a virus removal. To reset your restore points, please note that you will need to log into your computer with an account, which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. Win ME To disable System Restore: 1. Right-click My Computer, and then click Properties. 2. On the Performance tab, click File System, or press ALT+F. 3. On the Troubleshooting tab, click to select the Disable System Restore check box. 4. Click OK twice, and then click Yes when you are prompted to restart the computer. 5. To re-enable System Restore, follow steps 1-3, but in step 3, click to clear the Disable System Restore check box.
Hi,
I did disable and re-enable, and inbetween I ran trendmicro, eTrust, and TrojanScan. Nothing was found!

After the final booting I also ran Ad-Aware scan, and AVGAntivirus found "Trojan horse dialer 8.BA" again.

Here's HJT:

Logfile of HijackThis v1.98.2
Scan saved at 13.13.55, on 12/09/2004
Platform: Windows ME (Win9x 4.90.3000)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGSERV9.EXE
C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\OUTPOST.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAMMI\GRISOFT\AVG6\AVGCC32.EXE
C:\WINDOWS\SYSTEM\ICSMGR.EXE
C:\PROGRAMMI\ADAPTEC\EASY CD CREATOR 5\DIRECTCD\DIRECTCD.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\MY DOWNLOADS\HIJACKTHIS\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://security.kolla.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F1 - win.ini: run=c:\windows\alevir.exe,c:\windows\scrsvr.exe,c:\windows\marco!.scr
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [ICSMGR] ICSMGR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe
O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\RunServices: [Avgserv9.exe] C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe
O4 - HKLM\..\RunServices: [Outpost Firewall] C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKCU\..\Run: [SpamTerminator] C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.exe
O8 - Extra context menu item: Enqueue in Star Downloader - C:\PROGRAMMI\STAR DOWNLOADER\sdieenq.htm
O8 - Extra context menu item: &Download with DownloadPlus! - C:\PROGRAMMI\DOWNLOADPLUS\downloadplus.htm
O9 - Extra button: Organizzatore ricerche - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programmi\File comuni\Microsoft Shared\Reference 2001\EROProj.dll
O12 - Plugin for .pdf: C:\PROGRA~1\INTERN~1\PLUGINS\nppdf32.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://apple.speedera.net/qtinstall.info.a…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
Quite often Windows O/S's may not be able to see hidden DLL files that may be spyware related. Option^Explicit has come up with a way to scan any version of Windows for these files.
  • Please download dllcompare (A scanner to locate hidden DLL files) from either of the following locations:
  • When you execute dllcompare.exe, by default the c:\windows\system32 is selected. This can be changed to scan you entire computer for any file type - Simply select the path and check off the box labelled "Include SubDirectories"
  • Click on "Locate.com" and allow the scan to complete.
  • After the scan has finished click on "Compare" to scan for the files that Windows does not see. This step will take a few minutes to run.
  • If the box at the bottom of the screen contains any files, these are the ones that are hidden - Click on "Make a Log of what was Found".
  • When prompted to "View Log File" click on "Yes".
  • Notepad will open with the log file contents.
  • In Notepad, click on "Edit" => "Select All" => "Edit" = "Copy" and post the contents as a reply to this message.
There are no function in the program to alter the O/S as it is just a scanner at this point.
Hi, here is the .dllscan * DLLCompare Log version() Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\PROGRA~1\ACCESS~1\mspcx32.dll Thu 8 Jun 2000 17.00.00 …H. 53.248 52,00 K C:\PROGRA~1\ACCESS~1\HYPERT~1\hypertrm.dll Thu 8 Jun 2000 17.00.00 …H. 591.120 577,27 K C:\PROGRA~1\ACCESS~1\HYPERT~1\hticons.dll Thu 8 Jun 2000 17.00.00 …H. 29.456 28,77 K ________________________________________________ 2.411 items found: 2.411 files (3 H/S), 0 directories. Total of file sizes: 519.077.480 bytes 495,03 M ——————–End log———————
while downloading TDS3 and update, I got another couple of the by now usual Opas viruses. After downloading, AVGantivirus got rid of the bugs and I cleaned (execute) win.ini


[windows]
load=
run=
NullPort=None
device=NEC Pinwriter P2200,NEC24PIN,LPT

Then I did a TDS3 full system scan:

07.26.32 [Init] Trojan Defence Suite v3.2.0 (UNLICENSED)
07.26.32 [Init] Started 13-09-04 07.26.32 ora solare Europa occ. (UTC: -1), Internet Time @268,43
07.26.32 [Init] Loading TDS-3 Systems …
07.26.32 [Init] Token successfully adjusted.
07.26.32 [Init] • TDS Privileges : OK. Adjusted TDS-3 token privileges to maximum
07.26.33 [Init] • Plugins : OK. Loaded 13
07.26.33 [Init] • Exec Protection : Not Installed
07.26.33 [Init] WARNING: Your Radius.TD3 database needs to be updated!
07.26.33 [Init] Please download the latest from http://tds.diamondcs.com.au/radius.td3
07.26.33 [Init] Licensed users can use the Update facility from the TDS menu
07.26.34 [Init] Loading Radius Advanced Scanning Systems …
07.26.48 [Init] • Radius Advanced Specialist Extensions on standby for 13 trojan families
07.26.48 [Init] • Systems Initialised [37546 references - 15213 primaries/10384 traces/11949 variants/other]
07.26.48 [Init] Radius Systems loaded.
07.26.48 [Init] TDS-3 Ready. <@0.0.0.0, 0.0.0.0, 127.0.0.1, 0.0.0.0 - italy>
07.26.48 [Tip Of The Day] If you're suspicious about a certain file, use the String Extractor (from the Utilities menu). This will run through the file and strip out ANSI strings of 5 characters or more in length, enabling you in some cases to get a better 'view' of the file.
07.26.48 [TDS] Good morning Operator. Go back to bed - you know you want to!
07.26.56 [Mutex Memory Scan] Started…
07.26.57 [Mutex Memory Scan] Finished (no trojan mutexes found).
07.26.57 [Trace Scan] Started…
07.27.23 [Trace Scan] Finished.
07.27.23 [TDS-3] NOTICE - TDS-3 was not properly shut down.
07.27.23 [TDS-3] This is an EVALUATION demo of TDS-3. Please see the help file for help on registering.
07.28.52 [CRC32] Started - verifying 29 files …
07.28.53 [CRC32] File doesn't exist: C:\WINDOWS\System\cmd.exe
07.28.54 [CRC32] File doesn't exist: C:\WINDOWS\System\netstat.exe
07.28.55 [CRC32] File doesn't exist: C:\WINDOWS\System\drwatson.exe
07.28.56 [CRC32] File doesn't exist: C:\WINDOWS\System\drwtsn32.exe
07.28.56 [CRC32] File doesn't exist: C:\WINDOWS\System\rundll32.exe
07.28.57 [CRC32] File doesn't exist: C:\WINDOWS\System\sysedit.exe
07.28.58 [CRC32] File doesn't exist: C:\WINDOWS\System\taskman.exe
07.29.00 [CRC32] File doesn't exist: C:\WINDOWS\System\taskmgr.exe
07.29.00 [CRC32] File doesn't exist: C:\WINDOWS\System\winlogon.exe
07.29.01 [CRC32] File doesn't exist: C:\WINDOWS\System\regedt32.exe
07.29.02 [CRC32] File doesn't exist: C:\WINDOWS\System\netmsg.dll
07.29.04 [CRC32] File doesn't exist: C:\WINDOWS\System\winsock.dll
07.29.08 [CRC32] Test finished.
07.30.53 [Memory Scan] Memory scan started, please wait a moment …
07.31.02 [Memory Scan] Memory scan complete.
07.31.02 [Mutex Memory Scan] Started…
07.31.04 [Mutex Memory Scan] Finished (no trojan mutexes found).
07.31.04 [Trace Scan] Started…
07.31.30 [Trace Scan] Finished.
07.31.30 [ServiceScan] Scanning for services and drivers …
07.31.30 [ServiceScan] Scanned 24 services and drivers.
07.31.30 [File Scan] Scanning in A:\ …
07.31.33 [File Scan] Scanned 0 files: 0 alarms in 2,138672 seconds (Avg 1, files/sec)
07.31.33 [File Scan] Scanning in C:\ …
08.38.15 [File Scan] Scanned 52911 files: 6 alarms in 4002,26 seconds (Avg 14,22 files/sec)
08.38.16 [File Scan] Scanning in D:\ …
08.44.55 [File Scan] Scanned 2353 files: 6 alarms in 398,7617 seconds (Avg 6,9 files/sec)
08.44.57 [File Scan] Scanning in E:\ …
08.44.57 [File Scan] Scanned 0 files: 6 alarms in 0 seconds (Avg -1,#IND files/sec)
08.44.57 [File Scan] Scanning in F:\ …
08.44.57 [File Scan] Scanned 0 files: 6 alarms in 0 seconds (Avg -1,#IND files/sec)
08.44.57 [File Scan] Scanning in G:\ …
08.44.57 [File Scan] Scanned 0 files: 6 alarms in 0 seconds (Avg -1,#IND files/sec)
08.44.57 [File Scan] Scanning in H:\ …
08.44.57 [File Scan] Scanned 0 files: 6 alarms in 0 seconds (Avg -1,#IND files/sec)
08.44.58 [Scan] Finished.
08.50.06 [Screen Text] Saved to C:\PROGRAMMI\TDS3\scr0.txt

HELP
When I connected to post my previous message, I got more Opas viruses: Results of Complete Test, date and time 13/09/2004 11.29.47 : Testing C:\ volume DISCO C serial 252C-16EA C:\WINDOWS\BRASIL.PIF Virus identified Win32/Dupator C:\WINDOWS\NATAL.SCR repaired and this is my startup list: Spybot-S&D Startup list report, 13/09/2004 11.27.46 Located: HK_CU:Run, SpamTerminator file: C:\PROGRAMMI\SPAM TERMINATOR\TERMINATOR.exe MD5: 78E50DD1761BDC48833B291775B175C1 Located: HK_LM:Run, TaskMonitor file: C:\WINDOWS\taskmon.exe MD5: 0A289B97B1CD93187B3871165C7FB808 Located: HK_LM:Run, SystemTray file: SysTray.Exe Located: HK_LM:Run, LoadPowerProfile file: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme Located: HK_LM:Run, AVG_CC file: C:\PROGRA~1\GRISOFT\AVG6\avgcc32.exe /STARTUP Located: HK_LM:Run, ICSMGR file: ICSMGR.EXE Located: HK_LM:Run, QuickTime Task file: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime Located: HK_LM:Run, TkBellExe file: "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot Located: HK_LM:Run, AdaptecDirectCD file: "C:\Programmi\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" Located: HK_LM:Run, Outpost Firewall file: C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /waitservice Located: HK_LM:Run, PCHealth (DISABLED) file: C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s Located: HK_LM:Run, EM_EXEC (DISABLED) file: C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE MD5: 692C2BE43C8A88597DDE63EDF2682033 Located: HK_LM:Run, QuickTime Task (DISABLED) file: "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime Located: HK_LM:Run, ScanRegistry (DISABLED) file: C:\WINDOWS\scanregw.exe /autorun Located: HK_LM:RunServices, SchedulingAgent file: mstask.exe Located: HK_LM:RunServices, *StateMgr file: C:\WINDOWS\System\Restore\StateMgr.exe MD5: 18A1C6E0F07CC34677E3EC23ED41185C Located: HK_LM:RunServices, StillImageMonitor file: C:\WINDOWS\SYSTEM\STIMON.EXE MD5: F078209D5685359CFF51367308932D5B Located: HK_LM:RunServices, Avgserv9.exe file: C:\PROGRA~1\GRISOFT\AVG6\Avgserv9.exe MD5: CF63AAE9020129B18D452870EC6CBE7B Located: HK_LM:RunServices, Outpost Firewall file: C:\PROGRAMMI\AGNITUM\OUTPOST FIREWALL 1.0\outpost.exe /service Located: HK_LM:RunServices, LoadPowerProfile file: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme Located: win.ini, Run (DISABLED) file: c:\windows\Brasil.pif,c:\windows\natal.scr
sorry, I'm beginning to feel lilke I'm on thin ice. I wanted to add that I ran AdAware again and my trojan horse dialer 5.BA is still there. thanks

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI