Wow… 14 Trojans (I think) deleted!!!
I ran TDS3 prior to anything else. I downloaded the update, but for some reason I don't think I have it totally up to date. It states that it updates daily, but the definitions I have are from Aug 04 (I think). Even at that, It came up with a list of 10 trojans. I was able to delete 9 of them from the program. fdrest.exe and nodes.exe were two of them. I have included the log below. The one that I was not able to delete within TDS3 was msacmx.dll. However, later I went into Safe Mode and deleted it from there. One other file was unable to be opened… Windows\System32\clfmon.exe was listed as a read access, locked file. I don't know about that file…you have any ideas? I did not delete it, and won't unless instructed.
The following were files we discussed but were NOT found by TDS3…
cople.exe, ssysprs.dll, setupzmp.dll, wutop.exe. You had indicated that the last 3 were bad, so I deleted them. I decided to also delete cople, as it was "created" at exactly the same time as the others, and the source of the file was unknown. I have a zipped copy just in case.
I am very hopeful that this will take care of the problem. After running TDS3, I rebooted and ran CSShredder, AdAware, SpyBot, and SpySweeper (all from Safe mode). The only thing that ever came up was the DSO Exploit (within SpyBot I think). That is one that you said is not anything to worry about. There were 4 entries within it, whereas each time before I have had 5 entries.
Could you please take a look at my most recent log from HJT? Thanks a ton. I am also including the log from TDS3 for your info.
TDS3 log
Scan Control Dumped @ 20:52:04 08-12-04
(DELETED) Positive identification: TrojanClicker.Win32.Small.cg
File: c:\windows\system32\mqbckup.exe
(DELETED) Positive identification: TrojanDropper.Win32.Tibsis.a1
File: c:\windows\fdrest.exe
(DELETED) Positive identification : Possible WebDownloader
File: c:\windows\nodes.exe
(DELETED) Positive identification (DLL): Trojan.Win32.Agent.r1 (dll)
File: c:\windows\system32\d3dxov.dll
(DELETED) Positive identification (embedded in file): TrojanDownloader.Win32.Agent.av2 (dll)
File: c:\windows\system32\dllhostxp.exe
(DELETED) Positive identification: TrojanDownloader.Win32.Agent.av1 Dropper
File: c:\windows\system32\dllhostxp.exe
(DELETED) Positive identification: TrojanClicker.Win32.Small.cg
File: c:\windows\system32\mqbckup.exe
Positive identification (DLL): TrojanDownloader.Win32.Agent.av2 (dll)
File: c:\windows\system32\msacmx.dll
(DELETED) Positive identification (embedded in file): TrojanDownloader.Win32.Agent.av2 (dll)
File: c:\windows\system32\slservc.exe
(DELETED) Positive identification (DLL): Trojan.Win32.Agent.r2 (dll)
File: c:\windows\system32\winsrv32.dll
HJT Log
Logfile of HijackThis v1.98.2
Scan saved at 10:34:48 PM, on 12/8/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://education.dellnet.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SpoofStick BHO - {CBA74CDA-DF78-4AD9-954E-3B15D0A993DE} - C:\Program Files\CoreStreet\SpoofStick\SpoofStickBHO.dll
O3 - Toolbar: SpoofStick - {4D46ED77-1429-4CF6-8F63-C84B5D710BAF} - C:\Program Files\CoreStreet\SpoofStick\SpoofStick.dll
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe"
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: Epson all-in-one Registration.lnk = D:\Titles\EpsonReg\EPSONREG.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) -
http://www.ravantivirus.com/scan/ravonline.cab