The following was extracted from the AVG log. The execom stuff is part of one of my programs and is not a virus.
"C:\MyDisk\JIGSAW\JIGSAW\WWW\STATE\JULY5\TEMPLA~1.DAT","Could be infected W97M/Ethan","Infected"
"C:\MyDisk\OPEN\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\EXECOM.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\Back\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\OpenDev\Execom\Execom2\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\MyDisk\OpenV\OpenDev\Execom\Execom2\_XECOM.$$$","Suspicion: unknown virus .TSR","Infected"
"C:\OPEN\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\EXECOM.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Back\Execom.BAK","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Back\Execom.exe","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\Old\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\OpenDev\Execom\Execom2\EXECOM.EXE","Suspicion: unknown virus .TSR","Infected"
"C:\OpenV\OpenDev\Execom\Execom2\_XECOM.$$$","Suspicion: unknown virus .TSR","Infected"
"C:\Downloads\Anti-Parasite\KillBox\crsss.exe","","Deleted"
"C:\Downloads\Anti-Parasite\KillBox\syshost.exe","","Deleted"
"C:\WINDOWS\MatAdown.dll","","Deleted"
"C:\WINDOWS\system32\MatAdown.dll","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\DF7ZLTIR\istsvc[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet
Files\Content.IE5\J20ZYTGA\bobby[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet
Files\Content.IE5\P8UJHVWL\istrecover[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\x[1].exe","","Deleted"
"C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\x[2].exe","","Deleted"
Then I decided to “go round again”, rebooting the machine after using each utility.
First I ran RegCleaner – Tools > RegCleanup > Do them all > select all > delete.
Then I did Start > Run > %temp% and tried to delete the contents of the directory. It said “Cannot delete Perflib_Perfdata_1d4.dat. It is being used by another person or program.” Also, KillBox could not delete it.
Then I did Control Panel > Internet Options > General > Delete Files > Offline content > ok.
Then I did Start > Run > cleanMgr on Temporary Files, Temporary Internet Files and Recycle Bin. While in cleanMgr, I looked at its list of installed programs. I don’t know what DeskAd Services and Windows ServeAd are.
Then I ran Stinger and this is the log.
McAfee AVERT Stinger Version 2.4.7 built on Jan 3 2005
Copyright © 2004 Networks Associates Technology, Inc. All Rights Reserved.
Virus data file v1000 created on Dec 14 2004.
Ready to scan for 47 viruses, trojans and variants.
Scan initiated on Thu Jan 13 14:22:30 2005
C:\!Submit\o
Found the W32/Sdbot.worm!ftp virus !!!
C:\!Submit\o has been deleted.
C:\WINDOWS\system32\o
Found the W32/Sdbot.worm!ftp virus !!!
C:\WINDOWS\system32\o has been deleted.
Number of clean files: 500972
Number of infected files: 2
Number of files deleted: 2
——————————————————————————————————-
Then I ran AdAware, SpyBot and AVG and cleaned/deleted as much as I could.
Then I ran the eSpan (mWav.exe) utility and it found the following (just seen your last post and I see I should ignore the !Submit items - I’ve just deleted the folder).
File C:\WINDOWS\System32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\winxpdriver.exe infected by "Backdoor.Win32.Wootbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\winxpdriver.exe infected by "Backdoor.Win32.Wootbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\zzz.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\mswe1.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\System32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\aRMlpbBvH.exe infected by "not-a-virus:AdWare.WinFetcher.c" Virus. Action Taken: No Action Taken.
File C:\!Submit\askjhfs3.exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\Config.sys tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\!Submit\DeskAdKeep.exe infected by "not-a-virus:AdWare.WinAD.k" Virus. Action Taken: No Action Taken.
File C:\!Submit\DLC[1].exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\!Submit\freedownload.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\!Submit\Inbox infected by "Macro.Word97.Marker.q" Virus. Action Taken: No Action Taken.
File C:\!Submit\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken.
File C:\!Submit\jhfhjj.exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\!Submit\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.b. No Action Taken.
File C:\!Submit\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken.
File C:\!Submit\mediaplayer.exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\!Submit\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken.
File C:\!Submit\ov.exe infected by "not-a-virus:AdWare.WinFetcher.b" Virus. Action Taken: No Action Taken.
File C:\!Submit\ringtone.exe tagged as not-a-virus:RiskWare.Dialer.PlayGames. No Action Taken.
File C:\!Submit\Sent infected by "Macro.Word97.Marker.q" Virus. Action Taken: No Action Taken.
File C:\!Submit\SexPress - UK.EXE tagged as not-a-virus:Porn-Dialer.Win32.Frelex. No Action Taken.
File C:\!Submit\systemupdate.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\!Submit\targetsaver[1].exe infected by "TrojanDownloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
File C:\!Submit\tmpf04.exe infected by "Backdoor.Win32.Haxdoor.az" Virus. Action Taken: No Action Taken.
File C:\!Submit\tmpf06.exe infected by "Backdoor.Win32.Haxdoor.az" Virus. Action Taken: No Action Taken.
File C:\!Submit\WebRebates0.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\!Submit\WebRebates1.exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\!Submit\WinServAd.exe infected by "not-a-virus:AdWare.WinAD.f" Virus. Action Taken: No Action Taken.
File C:\!Submit\WinServSuit.exe infected by "not-a-virus:AdWare.WinAD.h" Virus. Action Taken: No Action Taken.
File C:\Downloads\Anti-Parasite\HighjackThis\backups\backup-20050108-121417-120.dll infected by "not-a-virus:AdWare.Relevance.b" Virus. Action Taken: No Action Taken.
File C:\Downloads\IomegaWin98\ioware-w32-x86-402.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\My Downloads\Iomega\ioware-w32-x86-402.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy (2) of PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy (2) of PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy of PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\Copy of PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBCC2\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBDLL6\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBUPGR~1\setupcc.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\Downloads\PBUPGR~1\setupdll.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\JDK12~1.2\DEMO\APPLETS\BARCHART\Chart.class tagged as not-a-virus:JavaClass.Chart. No Action Taken.
File C:\MyDisk\LOSTFILE\DIR171\AOL\AOL40US.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\PROGRA~1\ONLINE~1\AT&T\ATTSETUP.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\MyDisk\WIN32API\WIN32API.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\AutoDisk\Setup_enu.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\DriveIcons\imghr.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\program files\Iomega\System32\Win2kDrivers.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\RECYCLER\undo.exe infected by "Trojan.WinREG.LowZones.a" Virus. Action Taken: No Action Taken.
File C:\trots.exe infected by "TrojanDropper.Win32.PurityScan.h" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\data[1].exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\DTBC[1].exe infected by "TrojanDownloader.Win32.Small.qd" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\J20ZYTGA\webrebates_europe[1].exe infected by "not-a-virus:AdWare.WebRebates.d" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\P8UJHVWL\data[1].exe infected by "TrojanDropper.Win32.Juntador.c" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\ESOWF.dll infected by "Backdoor.Win32.Haxdoor.ay" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\mswe1.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\navprotect.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\zzz.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
File C:\Zips\Backup Disk #2\Downloads1.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\Backup Disk #3\My Downloads.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\MyDisk1.zip tagged as not-a-virus:Porn-Dialer.Win32.Frelex. No Action Taken.
File C:\Zips\MyDisk2.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Zips\Program files.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
Finally I ran HJT and here is the log.
Logfile of HijackThis v1.99.0
Scan saved at 20:04:47, on 13/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\navprotect.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\System32\winxpdriver.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\navprotect.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\navprotect.exe
C:\program files\Microsoft Office\Office\OSA.EXE
C:\program files\WinZip\WZQKPICK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Downloads\Anti-Parasite\HighjackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.evesham.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://signup.e2binternet.com/cdsignup/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe -osboot
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\Run: [Windows Driver] winxpdriver.exe
O4 - HKLM\..\RunServices: [NAV Auto Protect] navprotect.exe
O4 - HKLM\..\RunServices: [Windows Driver] winxpdriver.exe
O4 - HKLM\..\RunOnce: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NAV Auto Protect] navprotect.exe
O4 - HKCU\..\Run: [Windows Driver] winxpdriver.exe
O4 - HKCU\..\RunOnce: [Windows Driver] winxpdriver.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\program files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\program files\Microsoft Office 2000\Office\OSA9.EXE
O4 - Global Startup: Office Startup.lnk = C:\program files\Microsoft Office\Office\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\program files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Get It With Kontiki - res://C:\Program Files\Kontiki\bin\bh304181.dll/201
O14 - IERESET.INF: START_PAGE_URL=http://www.evesham.com/
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://207.188.7.150/16ecf39562da2cd08715/netzip/RdxIE6.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: CTI Central Management - Unknown - C:\WINDOWS\cti.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Iomega Active Disk - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe