This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help – Coolwebsearch + Securybanks Phishing Trojan

44 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

It asks if I want to restore the old value, or accept the new. I have NOT been choosing either option…just been closing the program out. What should I do??

Accept the new

I also get a SpySweeper notification that 8 changes have been made to my IE Favorites (all things that I don’t want). Can I also go ahead and remove them?

remove them.

When I get on the net, I still have “pxhping.exe” virus showing up and getting deleted by McAfee.

not sure if this is a bug?

Might nee to print these instructios out or save them to a note pad.
Download and Install and update but do not run Ad-Aware SE

Downloaded and Install and update donot run Spybot S&D


Download CWShredder check for updates.
http://www.downloads.subratam.org/CWShredder.exe

After downloading all of these. Disconnect from the Internet. Remove spyware guard will install it later and Disable SpySweeper we do not want it to start up on reboot.

Run Ad-Aware SE However, some of the settings will need to be changed before your first scan.
Close ALL windows except Ad-Aware SE
1) In the ‘General’ window make sure the following are selected in green:
*Automatically save log-file
*Automatically quarantine objects prior to removal
*Safe Mode (always request confirmation)
Under Definitions:
*Prompt to udate outdated definitions - set the number of days
2) Click on the ‘Scanning’ button on the left and select in green :
Under Driver, Folders & Files:
*Scan Within Archives
Under Select drives & folders to scan -
*choose all hard drives
Under Memory & Registry: all green
*Scan Active Processes
*Scan Registry
*Deep Scan Registry
*Scan my IE favorites for banned URL’s
*Scan my Hosts file
3) Click on the ‘Advanced’ button on the left and select in green:
Under Shell Integration:
*Move deleted files to recycle bin
Under Logfile Detail Level: (all green)
*include addtional object information
*DESELECT - include negligible objects information
*include environment information
Under Alternate Data Streams:
*Don't log streams smaller than 0 bytes
*Don't log ADS with the following names: CA_INOCULATEIT
4) Click the ‘Tweak’ button and select in green:
Under the ‘Scanning Engine’:
*Unload recognized processes during scanning
*Scan registry for all users instead of current user only
Under the ‘Cleaning Engine’:
*Let Windows remove files in use at next reboot
Under the Log Files:
*Include basic Ad-aware SE settings in logfile
*Include additional Ad-aware SE settings in logfile
*Please do not check or make green: Include Module list in logfile
5. Click on ‘Proceed’ to save the settings.
6. Click ‘Start’
*Choose:'Perform Full System Scan'
*DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
7. Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
8. If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window
9. Save the log file when it asks and then click ‘finish’
10. REBOOT to complete the removal of what Ad-Aware SE found


Scanning in Spybot Search and Destroy:
In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.
Close ALL windows except Spybot S&D Next click the button ‘Check for Problems’
When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window
Make certain there is a check mark beside all of the RED entries ONLY.
Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.
REBOOT to complete the scan and clear memory.

Run CWShredder to clean up clicking "FIX" to have it remove all it finds. Reboot and then:

Run these two of the Virus scans. Make sure autoclean is enabled on the scans
http://www.pandasoftware.com/activescan/co…n_principal.htm
http://www.ravantivirus.com/scan/
Note any thing that can't be fixed

And this anti-trogan scan
http://www.anti-trojan.net/en/onlinecheck.aspx

Reboot and post another log.
Just thought I'd let you know… I am in the progress of doing your instructions. So far… Adaware found nothing SpyBot only showed 2 items in Red. Nothing in Black or Green. The two red items were NewsUpdate (7 entries) and DSO Exploit (5 entries). I "Fixed" both. Message came up that it fixed 11 of the 12 entries. Couldn't fix the other (one of the NewsUpdate entries) because it couldn't find the MFC42D.dll file. Said I should reboot and that might fix it, then rerun SpyBot. I did so, and nothing called NewsUpdate has come up again. However, after the reboot DSO Exploit (Exact same 5 entries) came up again. I clicked on Fix, and it says it did. Just for fun (!) I rebooted and ran SpyBot again. AGAIN DSO Exploit (Exact same 5 entries) came up. I fixed again, rebooted. I did not run it again. Currently I am getting ready to run the virus scans you requested. Just thought I'd let you know about SpyBot. Will post again after scans.
Just thought I'd let you know… I am in the progress of doing your instructions. So far… Adaware found nothing SpyBot only showed 2 items in Red. Nothing in Black or Green. The two red items were NewsUpdate (7 entries) and DSO Exploit (5 entries). I "Fixed" both. Message came up that it fixed 11 of the 12 entries. Couldn't fix the other (one of the NewsUpdate entries) because it couldn't find the MFC42D.dll file. Said I should reboot and that might fix it, then rerun SpyBot. I did so, and nothing called NewsUpdate has come up again. However, after the reboot DSO Exploit (Exact same 5 entries) came up again. I clicked on Fix, and it says it did. Just for fun (!) I rebooted and ran SpyBot again. AGAIN DSO Exploit (Exact same 5 entries) came up. I fixed again, rebooted. I did not run it again. Currently I am getting ready to run the virus scans you requested. Just thought I'd let you know about SpyBot. Will post again after scans.
Updated news…Some of it I think(?) is good!

I already told you about the problem with SpyBot and the DSO Exploit that continues to come back. I then ran CWShredder and it found nothing.
Pandasoftware Virus scan found nothing.

Then RAV antivirus found something…

Scanning memory…
Scanning boot sectors…
Scanning files…
C:\Diploma\Brgsetup.exe - Trojan:Win32/AOL.PS.ID -> Suspicious
C:\WINDOWS\SYSTEM\124529.exe - Tool:PornDialer.BP -> Infected

Scanned
============================
Objects: 72157
Directories: 4226
Archives: 5079
Size(Kb): 638145
Infected files: 1
Found
============================
Viruses found: 1
Suspicious files: 1
Disinfected files: 0
Mail files: 39

RAV did NOT automatically delete the virus file C:\WINDOWS\SYSTEM\124529.exe - Tool:PornDialer.BP even though I had it set to autoclean. The software informed me that sometimes the file has to be manually deleted. I went to the system folder and found the file. The icon of the file was a girl’s face. Furthermore, the date the file was created was 11-17, which was the date of my computers infection. So I did a shift/delete on it. After rebooting in Safe mode, the file was still gone. After rebooting regular it was still gone!

Next, I tried to do the anti Trojan scan, however, your link has been discontinued. I went to anti-trojan.net and it says that it has a new link for a new program called a(squared) free from emsisoft.com. I did NOT run it. I thought I’d let you check it out, or recommend another scanner.

Prior to rebooting I also ran SpyBot again, and it again found DSO Exploit. I had it deleted again. I wanted to get rid of it one more time before rebooting with the idea that it “might” be somehow connected with the virus file mentioned above. I do not know if it came back or not. I will probably run SpyBot again after I post.

BUMMER…Just opened IE and again got a message from McAfee about deleting the pxhping.exe virus file from the Windows System32 directory.
???????????

Here is my new log.

Logfile of HijackThis v1.98.2
Scan saved at 7:52:44 PM, on 12/5/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\WINDOWS\System32\msacmx.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:%
Sorry… I still have the same problem!!!!!!!!!!!

As soon as I hit "Add Reply" it went to the same girlsforgames website!@#$@
I saw where part of my log got posted, but not all. Let me try again!!!

Here is the entire message again!


Updated news…Some of it I think(?) is good!

I already told you about the problem with SpyBot and the DSO Exploit that continues to come back. I then ran CWShredder and it found nothing.
Pandasoftware Virus scan found nothing.

Then RAV antivirus found something…

Scanning memory…
Scanning boot sectors…
Scanning files…
C:\Diploma\Brgsetup.exe - Trojan:Win32/AOL.PS.ID -> Suspicious
C:\WINDOWS\SYSTEM\124529.exe - Tool:PornDialer.BP -> Infected

Scanned
============================
Objects: 72157
Directories: 4226
Archives: 5079
Size(Kb): 638145
Infected files: 1
Found
============================
Viruses found: 1
Suspicious files: 1
Disinfected files: 0
Mail files: 39

RAV did NOT automatically delete the virus file C:\WINDOWS\SYSTEM\124529.exe - Tool:PornDialer.BP even though I had it set to autoclean. The software informed me that sometimes the file has to be manually deleted. I went to the system folder and found the file. The icon of the file was a girl’s face. Furthermore, the date the file was created was 11-17, which was the date of my computers infection. So I did a shift/delete on it. After rebooting in Safe mode, the file was still gone. After rebooting regular it was still gone!

Next, I tried to do the anti Trojan scan, however, your link has been discontinued. I went to anti-trojan.net and it says that it has a new link for a new program called a(squared) free from emsisoft.com. I did NOT run it. I thought I’d let you check it out, or recommend another scanner.

Prior to rebooting I also ran SpyBot again, and it again found DSO Exploit. I had it deleted again. I wanted to get rid of it one more time before rebooting with the idea that it “might” be somehow connected with the virus file mentioned above. I do not know if it came back or not. I will probably run SpyBot again after I post.

BUMMER…Just opened IE and again got a message from McAfee about deleting the pxhping.exe virus file from the Windows System32 directory.
???????????

Here is my new log.

Logfile of HijackThis v1.98.2
Scan saved at 7:52:44 PM, on 12/5/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\WINDOWS\System32\msacmx.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Program Files\CoreStreet\SpoofStick\SpoofStickBHO.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Epson all-in-one Registration.lnk = D:\Titles\EpsonReg\EPSONREG.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
Just FYI SpyBot again found the same 5 entries. I figured out how to copy them to the clipboard. Here are the five. I hope this helps. DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\S-1-5-21-1858025970-4264649163-3499916212-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 DSO Exploit: Data source object exploit (Registry change, nothing done) HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3 — Spybot - Search && Destroy version: 1.3 — 2004-11-29 Includes\Cookies.sbi 2004-12-01 Includes\Dialer.sbi 2004-12-02 Includes\Hijackers.sbi 2004-12-01 Includes\Keyloggers.sbi 2004-05-12 Includes\LSP.sbi 2004-12-01 Includes\Malware.sbi 2004-11-29 Includes\Revision.sbi 2004-11-29 Includes\Security.sbi 2004-12-01 Includes\Spybots.sbi 2004-11-29 Includes\Tracks.uti 2004-12-01 Includes\Trojans.sbi
The Spybot DSO Exploit is just a well known bug nothing to worry about.

I went to anti-trojan.net and it says that it has a new link for a new program called a(squared) free from emsisoft.com.

you can go ahead and run it.

Next, I tried to do the anti Trojan scan, however, your link has been discontinued. I went to anti-trojan.net and it says that it has a new link for a new program called a(squared) free from emsisoft.com. I did NOT run it. I thought I’d let you check it out, or recommend another scanner.

thanks I'll try to remember to change that .


Before you run the scanner can you go to C:\WINDOWS\SYSTEM\124529.exe right click on it and zip it up and send it to me here
I will try the anti trojan site. I'm sorry I can't send you the virus file. I deleted it. I then searched my hard drive just to make sure I didn't have the same file somewhere else. The drive came up clean. The only knowledge I have on it is what I mentioned earlier.
The anti-trojan software had to be downloaded and run from the computer. Lots of updates to it, but finally got it. It came up with nothing! Bummer.

Here is my new log. Any ideas?

Logfile of HijackThis v1.98.2
Scan saved at 12:23:17 AM, on 12/6/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\WINDOWS\System32\msacmx.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Program Files\CoreStreet\SpoofStick\SpoofStickBHO.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - Startup: Epson all-in-one Registration.lnk = D:\Titles\EpsonReg\EPSONREG.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
Hey, I awoke this AM with an insight. Since I knew the date of infection, I ran a search of the files that were created/modified on that date. I have 8 files, all in the windows or windows/debug or windows/system32 directories. I took a picture (printscreen) of them and pasted into word. Would you like me to send you a copy of the word file to your email in the previous msg?? All of these files were timed within 20 minutes of each other.
Sorry, I didn’t have time earlier to give you a list of the files I found (mentioned in my last post). I am pretty sure, according to my family, that the infection occurred on 11-17, approx 4:15. Well, the infected file that I deleted yesterday was dated 11-17, time 4:17. When I searched my computer for all files created or modified on that day, I got the following list. File Folder Size Time Cople.exe Windows 24 kb 4:18 p Fdrest.exe Windows 191 kb 4:19 p Nodes.exe Windows 4 kb 4:20 p Setupzmp.dll Windows 72 kb 4:20 p Ssysprs.dll Windows 160 kb 4:17 p Wutop.exe Windows 19 kb 4:17 p “blank- no name” Windows\System32 1 kb 4:42 p ** This is a shortcut to MS-DOS Dcpromo.log Windows\Debug 17 kb 4:34 p I have not deleted anything yet, and will wait for your instructions.
Download FxAgentB.exe from HERE and save it to your desktop.

If you are on a network or have a full-time connection to the Internet, such as a DSL or cable modem, disconnect the computer from the network and Internet. Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet.

Double-click the FxAgentB file to run it and the program will scan your entire hard drive - this may take a while. When it is done, it will generate a log file called FxAgentB.log - save that information as you will need to paste it here later. Reboot when done.

Next run CWShredder click fix Reboot when done.

Then run Ad-Aware SE same setting as before.

Reboot when done, rescan with HijackThis and post a new log here, together with the FxAgentB log.

I took a picture (printscreen) of them and pasted into word.  Would you like me to send you a copy of the word file to your email in the previous msg??  All of these files were timed within 20 minutes of each other.

yes and the files zipped if you have them.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI