This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Email Sending With Out Me Doing It.

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Have ran Panda, House Call and Ad-Aware and still doing it. Here are my HiJack Logs

Logfile of HijackThis v1.99.0
Scan saved at 2:54:08 PM, on 12/30/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\eM\Bay Reader\Shwicon2k.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Messenger\msmsgs.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\PROGRA~1\ICQ\ICQ.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\UltraVNC\winvnc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AnalogX\Proxy\proxy.exe
C:\Program Files\Crazy Browser\Crazy Browser.exe
G:\Eudora\Eudora.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jinman.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - g:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [showicon2k] C:\Program Files\\eM\Bay Reader\Shwicon2k.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe"
O4 - Startup: log-old.rtf
O4 - Startup: log.rtf
O4 - Startup: Profiles.dat
O4 - Startup: SecCopy.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
Hi and welcome to the forum. :D

Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/download4086.html

REBOOT

Step #2

Please download and run Spybot & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do a virus scan here >>> Trend Micro

Reboot and post a new HiJackThis log.
Followed your directions and the ones for Spybot and Ad-Aware and then ran House Call and it found nothing and before I got to reboot I was trying to send the bogus Emails again. Here are the HiJackthis Logs:
Thanks,
John L. Inman

Logfile of HijackThis v1.99.0
Scan saved at 2:13:09 PM, on 1/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\eM\Bay Reader\Shwicon2k.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\PROGRA~1\McAfee.com\Agent\mcupdui.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\ICQ\ICQ.exe
G:\Programs\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jinman.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - g:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [showicon2k] C:\Program Files\\eM\Bay Reader\Shwicon2k.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe"
O4 - Startup: log.rtf
O4 - Startup: Profiles.dat
O4 - Startup: SecCopy.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
Please boot to safe mode (tap f8 while bios load) then scan with hijackthis and put a check beside these lines and choose FIX

O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\PROGRA~1\AWS\WEATHE~1\Weather.exe (HKCU)

O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?

Then reboot. I would like you to do another online scxan here >>> Panda

Then post a new log.
Did all steps and Panda found nothing. Here are the new HiJackthis Logs:

Logfile of HijackThis v1.99.0
Scan saved at 8:48:41 PM, on 1/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\eM\Bay Reader\Shwicon2k.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\WINDOWS\system32\drivers\dcfssvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\ICQ\ICQ.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Crazy Browser\Crazy Browser.exe
G:\Programs\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jinman.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - g:\Program Files\WS_FTP Pro\wsbho2k0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [showicon2k] C:\Program Files\\eM\Bay Reader\Shwicon2k.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe"
O4 - Startup: log.rtf
O4 - Startup: Profiles.dat
O4 - Startup: SecCopy.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)
Is it still dialing out?

If so do a scan here http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added. It will take some time to scan so no rush on it. When the scan is complete it will produce a log in the lower of 2 boxes on the scanner. Please copy and paste that log here, it could be large.
Still sending bogus Emails at times every day. When I did scan it told me I had to purchase there software to clean out virus’s. Is that correct?
John L. Inman

Here are the logs:
You were right, file awful large. I removed all individual files. If you need them Email me your Email address and I will send a Word File with all of them.
Thanks,


Wed Jan 05 09:48:10 2005 => **********************************************************
Wed Jan 05 09:48:10 2005 => eScan AntiVirus Toolkit Utility.
Wed Jan 05 09:48:10 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc.
Wed Jan 05 09:48:10 2005 => **********************************************************
Wed Jan 05 09:48:10 2005 => Version 4.7.7 (C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\mwavscan.com)
Wed Jan 05 09:48:10 2005 => Log File: C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\MWAV.LOG
Wed Jan 05 09:48:10 2005 => Latest Date of files inside MWAV: 05 Jan 2005 07:00:53.
Wed Jan 05 09:48:13 2005 => AV Library Loaded…
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\kavss.exe
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\Getvlist.exe
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\kavss.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\kavssdi.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\kavssi.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\kavvlg.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\msvlclnt.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\ipc.dll
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\main.avi
Wed Jan 05 09:48:13 2005 => Scanning File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\virus.avi
Wed Jan 05 09:48:13 2005 => Virus Database Date: 2005/01/05
Wed Jan 05 09:48:13 2005 => Virus Database Count: 114704

Wed Jan 05 09:49:31 2005 => **********************************************************
Wed Jan 05 09:49:31 2005 => eScan AntiVirus Toolkit Utility.
Wed Jan 05 09:49:31 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc.
Wed Jan 05 09:49:31 2005 =>
Wed Jan 05 09:49:31 2005 => Support: [removed]
Wed Jan 05 09:49:31 2005 => Web: http://www.mwti.net
Wed Jan 05 09:49:31 2005 => **********************************************************
Wed Jan 05 09:49:31 2005 => Version 4.7.7 (C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\mwavscan.com)
Wed Jan 05 09:49:31 2005 => Log File: C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\MWAV.LOG
Wed Jan 05 09:49:32 2005 => OS: Windows NT
Wed Jan 05 09:49:32 2005 => Latest Date of files inside MWAV: 05 Jan 2005 07:00:53.

Wed Jan 05 09:49:32 2005 => Options Selected by User:
Wed Jan 05 09:49:32 2005 => Memory Check: Enabled
Wed Jan 05 09:49:32 2005 => Registry Check: Enabled
Wed Jan 05 09:49:32 2005 => StartUp Folder Check: Enabled
Wed Jan 05 09:49:32 2005 => System Folder Check: Enabled
Wed Jan 05 09:49:32 2005 => System Area Check: Disabled
Wed Jan 05 09:49:32 2005 => Services Check: Enabled
Wed Jan 05 09:49:32 2005 => Drive Check: Disabled
Wed Jan 05 09:49:32 2005 => All Drive Check :Enabled
Wed Jan 05 09:49:32 2005 => Folder Check: Disabled


Wed Jan 05 11:32:18 2005 => Scanning File C:\Documents and Settings\Bev
Wed Jan 05 19:14:56 2005 => ***** Checking for specific ITW Viruses *****
Wed Jan 05 19:14:56 2005 => Checking for Welchia Virus…
Wed Jan 05 19:14:56 2005 => Checking for LovGate Virus…
Wed Jan 05 19:14:56 2005 => Checking for CodeRed Virus…
Wed Jan 05 19:14:56 2005 => Checking for OpaServ Virus…
Wed Jan 05 19:14:56 2005 => Checking for Sobig.e Virus…
Wed Jan 05 19:14:56 2005 => Checking for Winupie Virus…
Wed Jan 05 19:14:56 2005 => Checking for Swen Virus…
Wed Jan 05 19:14:56 2005 => Checking for JS.Fortnight Virus…
Wed Jan 05 19:14:56 2005 => Checking for Novarg Virus…
Wed Jan 05 19:14:56 2005 => Checking for Pagabot Virus…
Wed Jan 05 19:14:56 2005 => Checking for Parite.b Virus…
Wed Jan 05 19:14:56 2005 => Checking for Parite.a Virus…

Wed Jan 05 19:14:56 2005 => ***** Scanning complete. *****

Wed Jan 05 19:14:56 2005 => Total Files Scanned: 160327
Wed Jan 05 19:14:56 2005 => Total Virus(es) Found: 41
Wed Jan 05 19:14:56 2005 => Total Disinfected Files: 0
Wed Jan 05 19:14:56 2005 => Total Files Renamed: 0
Wed Jan 05 19:14:56 2005 => Total Deleted Files: 0
Wed Jan 05 19:14:56 2005 => Total Errors: 19
Wed Jan 05 19:14:56 2005 => Time Elapsed: 09:24:05
Wed Jan 05 19:14:56 2005 => Virus Database Date: 2005/01/05
Wed Jan 05 19:14:57 2005 => Virus Database Count: 114704

Wed Jan 05 19:14:57 2005 => Scan Completed.
There should have neeb a log that looked like this

File C:\WINDOWS\System32\amax.exe infected by "Trojan-Downloader.Win32.Agent.eb" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\CustIE32.dll infected by "Trojan.Win32.StartPage.po" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\EGCOMSERVICE_1048.dll tagged as not-a-virus:RiskWare.Dialer.E-Group.1048. No Action Taken.
File C:\WINDOWS\System32\iecust.dll infected by "Trojan.Win32.StartPage.sl" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\iecust.exe infected by "Trojan-Dropper.Win32.Small.ow" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\putes.exe infected by "Trojan.Win32.StartPage.po" Virus. Action Taken: No Action Taken.

Please download and run stinger and post the log from Micro Scan if you still have it.

http://vil.nai.com/vil/stinger/
I downloaded Stinger and here are there logs: McAfee AVERT Stinger Version 2.4.7 built on Jan 3 2005 Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved. Virus data file v1000 created on Dec 14 2004. Ready to scan for 47 viruses, trojans and variants. Scan initiated on Thu Jan 06 10:23:29 2005 Number of clean files: 360113 As o the other logs I do have them but they are about 36 MB in size and so big that when I try to past into this area the browser crashes. I can Zip them and Email them to you if you like. Maybe doing something wrong. What do you think. John L. Inman
In the lower box when you do the scan you should be able to copy and paste it into the thread. You do not need the items from the top box of the scan nor do you need to paste the log it creates.
Sorry about that. Reran it this morning and here are the logs: John L. Inman File C:\PROGRA~1\AnalogX\Proxy\proxy.exe tagged as not-a-virus:RiskWare.Proxy.AnalogX.414. No Action Taken. File C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\ICD1.tmp\hbinstie.dll infected by "not-a-virus:AdWare.ToolBar.Hotbar.t" Virus. Action Taken: No Action Taken. File C:\Documents and Settings\Bev Inman\Local Settings\Temp\ICD1.tmp\hbinstie.dll infected by "not-a-virus:AdWare.ToolBar.Hotbar.t" Virus. Action Taken: No Action Taken. File C:\Program Files\AnalogX\Proxy\proxy.exe tagged as not-a-virus:RiskWare.Proxy.AnalogX.414. No Action Taken. File C:\Program Files\AWS\WeatherBug\Weather.exe infected by "not-a-virus:AdWare.MiniBug" Virus. Action Taken: No Action Taken. File C:\Program Files\MySearch\bar\1.bin\NPMYSRCH.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\Program Files\MySearch\bar\1.bin\S42NS.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032576.exe infected by "not-a-virus:AdWare.Comet.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032579.dll infected by "not-a-virus:AdWare.ToolBar.ag" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032580.dll infected by "not-a-virus:AdWare.ToolBar.Hotbar.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032583.dll infected by "not-a-virus:AdWare.ToolBar.ag" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP293\A0038260.dll infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File G:\Programs\Coffee Cup\CoffeeBlocker20R.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeEffects20R.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeEffectsR20.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeStyleR40.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeZip20.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Internet Explorer 5.0 Plug-Ins\lpv3_22.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Access 97\wzsysadmin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Excel 97\dlg_conv.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Windows 98 Goodies\32bcr507.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Windows 98 Goodies\PK270WSP.EXE infected by "not-a-virus:AdWare.TimeSink" Virus. Action Taken: No Action Taken. File G:\Programs\downloads\Microsoft Word 97\fontlist.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Word 97\thesmenu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Screen Savers - Top Picks by McAfee\holits.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Integ checker\IntegrityCheckerInst.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\KAZAA\KazaaUpdate133a.exe infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File G:\Programs\Savings Bond Wiz\sbwsetup403.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Download and run KazaaBeGone from the link below.

http://www.spychecker.com/download/download_kazaagone.html

Then delete these folders/files

C:\DOCUME~1\BEVINM~1\LOCALS~1\Temp\ICD1.tmp\hbinstie.dll<< C:\Documents and Settings\Bev Inman\Local Settings\Temp\ICD1.tmp\hbinstie.dll<< C:\Program Files\AWS<< C:\Program Files\MySearch<<
Do you know what these programs are?

C:\Program Files\AnalogX\Proxy
G:\Programs\Coffee Cup

Then post a new log please.
I removed the files that you posted. Proxy is a proxy server that I am not using at this time so I removed it. I can always reinstall if I ever need it. Coffe Cup is a file that has downloaded software in it. I get the Coffe Cup software free from Blue Domino who hosts my Domain. Have not see any dialing out so far since I removed files so will leave up for the next 24 hours and see what happens. Thanks, John L. Inman Here are the logs: File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032576.exe infected by "not-a-virus:AdWare.Comet.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032579.dll infected by "not-a-virus:AdWare.ToolBar.ag" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032580.dll infected by "not-a-virus:AdWare.ToolBar.Hotbar.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP265\A0032583.dll infected by "not-a-virus:AdWare.ToolBar.ag" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP293\A0038260.dll infected by "TrojanDownloader.Win32.Rameh.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP300\A0040169.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.j" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP300\A0040170.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP300\A0040180.exe infected by "not-a-virus:AdWare.MiniBug" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{A5D9CCDE-791E-4D4F-821A-ADE141134902}\RP300\A0042312.exe tagged as not-a-virus:RiskWare.Proxy.AnalogX.414. No Action Taken. File G:\Programs\Coffee Cup\CoffeeBlocker20R.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeEffects20R.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeEffectsR20.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeStyleR40.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Coffee Cup\CoffeeZip20.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Internet Explorer 5.0 Plug-Ins\lpv3_22.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Access 97\wzsysadmin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Excel 97\dlg_conv.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Windows 98 Goodies\32bcr507.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Windows 98 Goodies\PK270WSP.EXE infected by "not-a-virus:AdWare.TimeSink" Virus. Action Taken: No Action Taken. File G:\Programs\downloads\Microsoft Word 97\fontlist.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Microsoft Word 97\thesmenu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\downloads\Screen Savers - Top Picks by McAfee\holits.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\Integ checker\IntegrityCheckerInst.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File G:\Programs\KAZAA\KazaaUpdate133a.exe infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File G:\Programs\Savings Bond Wiz\sbwsetup403.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Reran Hijackthis this morning and here is the log:

John L. Inman

Logfile of HijackThis v1.99.0
Scan saved at 6:12:04 AM, on 1/9/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\drivers\dcfssvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\eM\Bay Reader\Shwicon2k.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe
C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\UltraVNC\winvnc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Crazy Browser\Crazy Browser.exe
C:\Program Files\ICQ\Icq.exe
C:\Program Files\Organize Quick & Easy 5.0\AtDem.exe
C:\Program Files\Google\deskbar-0.5.95.0\ggviewer.exe
G:\Eudora\Eudora.exe
G:\Programs\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.jinman.org/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: CitiUS Shared Browser Helper Object - {387EDF53-1CF2-4523-BC2F-13462651BE8C} - C:\WINDOWS\System32\BhoCitUS.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Ipswitch.WsftpBrowserHelper - {601ED020-FB6C-11D3-87D8-0050DA59922B} - g:\Program Files\WS_FTP Pro\wsbho2k0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [showicon2k] C:\Program Files\\eM\Bay Reader\Shwicon2k.exe
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [CitiVAN] C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe /dontopenmycards
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Second Copy 2000] "C:\Documents and Settings\Bev Inman\Start Menu\Programs\Startup\SecCopy.exe"
O4 - HKCU\..\Run: [Organize Quick & Easy 5.0] C:\Program Files\Organize Quick & Easy 5.0\AtDem.exe
O4 - Startup: log-old.rtf
O4 - Startup: log.rtf
O4 - Startup: Profiles.dat
O4 - Startup: SecCopy.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\KODAK\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\KODAK\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Organize Quick & Easy 5.0.lnk = C:\Program Files\Organize Quick & Easy 5.0\Organize.exe
O4 - Global Startup: Run Ultr@VNC SERVER.lnk = C:\Program Files\UltraVNC\winvnc.exe
O4 - Global Startup: Shortcut to proxy.lnk = C:\Program Files\AnalogX\Proxy\proxy.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Citi - {4C730913-3961-439b-83D5-F4E445520422} - C:\Program Files\Citi Virtual Account Numbers\CitiVAN.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin5.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,20/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O17 - HKLM\System\CS1\Services\Tcpip\..\{3FEDA45A-D480-44D5-A1AF-2E90A69A050F}: NameServer = 216.220.0.1 204.70.57.242
O23 - Service: Dcfssvc - Eastman Kodak Company - C:\WINDOWS\system32\drivers\dcfssvc.exe
O23 - Service: McAfee.com McShield - Unknown - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService - Unknown - slserv.exe (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI