This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

adware spyware problems

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Perpetual problems on our Windows 2000 Server with about:blank reloading all the time despite removal in safe mode have use pandasoftware, cws shredder, sophos and symantec to remove trojans - running microsoft antispyware beta1 which now is advising that unclassified.spyware.65 is trying to load - it does too despite denying it. Zone Alarm installed as additional firewall but passes through. Seems to pick up BHO se.dll files when not connected to net sometimes - examples of .dll names usually in c:winnt\system32 are panonna.dll, enfm.dll, dgkm.dll, kolj.dll, jmlepa.dll, ahmflj.dll and so on always same size and same location - also about:blank references all over registry hkey local machine\software\microsoft\windows\currentversion\uninstall\searchassistantuninstall etc. This has been going on for weeks now and I clean it up daily … but not for long!! Please Help …. latest log this morning




Logfile of HijackThis v1.99.1
Scan saved at 10:55:49, on 05/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\Explorer.EXE
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\ZoneAlarm\zlclient.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\System32\mdm.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O2 - BHO: (no name) - {C84294F9-30C7-49EC-A3B0-9A3F87E19B74} - C:\WINNT\system32\lgof.dll
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\WINNT\TEMP\se.dll,DllInstall
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O18 - Filter: text/html - {DE118167-73F3-45CA-ADD8-5FD71F430B7D} - C:\WINNT\system32\lgof.dll
O18 - Filter: text/plain - {DE118167-73F3-45CA-ADD8-5FD71F430B7D} - C:\WINNT\system32\lgof.dll
O23 - Service: Sophos AutoUpdate Service (ActiveLinkClient) - Unknown owner - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Still needing advice with unclassified.spyware.65 - have cleaned up everything else for now but am expecting about:blank to come back anytime. Red Microsoft Antispyware warning unclassified.spyware.65 trying to install - Put Spywareblaster on last Friday seems to have held off things over the weekend but I don't know how - it seems to operate in the background with no warnings or prompts. Am also wondering if some of this spyware conflicts - Zone Alarm Sophos CWSShredder and Microsoft Atispyware ?
How did I know this was going to happen again ? :rant2:

Logfile of HijackThis v1.99.1
Scan saved at 07:41:27, on 12/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\System32\mdm.exe
C:\Program Files\Microsoft AntiSpyware\GIANTAntiSpywareMain.exe
C:\WINNT\system32\wuauclt.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O2 - BHO: (no name) - {C3BE0992-265A-4810-B33E-BAD459E1A841} - C:\WINNT\system32\fdj.dll
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\WINNT\TEMP\se.dll,DllInstall
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O18 - Filter: text/html - {6ABFF7F6-E573-43F9-AC1A-341BECE13ED2} - C:\WINNT\system32\fdj.dll
O18 - Filter: text/plain - {6ABFF7F6-E573-43F9-AC1A-341BECE13ED2} - C:\WINNT\system32\fdj.dll
O23 - Service: Sophos AutoUpdate Service (ActiveLinkClient) - Unknown owner - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe
Download CW-Shredder at the link below: (don't run it yet)
http://cwshredder.net/bin/CWShredder.exe

Download 'SpSeHjfix'. into a folder. (don't run it yet) http://www.derbilk.de/SpSeHjfix112.zip

Clean out temporary and TIF files. Go to Start > Run and type in the box: cleanmgr. Let it scan your system for files to remove. Make sure these 3 are checked and then press *ok* to remove:

Temporary Files
Temporary Internet Files
Recycle Bin

Make sure you know how to boot into - SafeMode

Reboot into safe mode.

Disconnect from the net and Close ALL OPEN PROGRAMS.
Run 'SpSeHjfix'. and click on "Start Disinfection".
When it's finished it will reboot your machine to finish the cleaning process.
The tool creates a log of the fix which will appear in the folder.

Now run the Shredder - Hit The FIX button!

Reboot and repeat the process above.

Reboot and post a fresh HJT log and the log that was created by 'SpSeHjfix'
Thank you very much for your assistance. I have had to do some cleanup already as Internet access was unavailable - removed some se.dll and about:blank and something in run registry. I then downloaded and ran the SPSeHjFix disinfect program and updated and ran the CWS shredder things seem clear right now - log below (5/16/05 14:03:25) SPSeHjFix started v1.1.2 (5/16/05 14:03:25) OS: Win2000 Service Pack 4 (5.0.2195) (5/16/05 14:03:25) Language: english (5/16/05 14:03:25) Win-Path: C:\WINNT (5/16/05 14:03:25) System-Path: C:\WINNT\system32 (5/16/05 14:03:25) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ (5/16/05 16:51:00) SPSeHjFix started v1.1.2 (5/16/05 16:51:00) OS: Win2000 Service Pack 4 (5.0.2195) (5/16/05 16:51:00) Language: english (5/16/05 16:51:00) Win-Path: C:\WINNT (5/16/05 16:51:00) System-Path: C:\WINNT\system32 (5/16/05 16:51:00) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ (5/16/05 16:51:11) Disinfection started (5/16/05 16:51:11) Bad-Dll(IEP): (not found) (5/16/05 16:51:11) Bad-Dll(IEP) in BHO: (not found) (5/16/05 16:51:11) UBF: 7 - UBB: 0 - UBR: 4 (5/16/05 16:51:11) UBF: 7 - UBB: 0 - UBR: 4 (5/16/05 16:51:11) Bad IE-pages: deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Default_Search_URL: deleted: HKCU\Software\Microsoft\Internet Explorer, SearchURL: (5/16/05 16:51:12) Stealth-String not found (5/16/05 16:51:12) Not infected->END I am cautiously optimistic as I have been here before - I am running ZoneAlarm and am denying anything I do not know on the Alerts. The unclassified.spyware.65 seems to blast right through and the Microsoft Antispyware advises me that defaults have changed afterwards ! I am going to have a cup of tea now and try to find out what ALC Agents are as they are on ZoneAlarm.
Log from this morning - Sophos reports 5 viruses

Logfile of HijackThis v1.99.1
Scan saved at 06:49:18, on 19/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\System32\svchost.exe
F:\Program Files\Sophos\Remote Management System\ALCAgent.exe
C:\WINNT\Explorer.EXE
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
F:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\system32\wuauclt.exe
F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Internet Explorer\iexplore.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O2 - BHO: (no name) - {EE0DD88F-0A97-4C1D-902D-AEA47E605D79} - C:\WINNT\system32\khjjpee.dll
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [sp] rundll32 C:\WINNT\TEMP\se.dll,DllInstall
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O18 - Filter: text/html - {9F76EA5E-A402-4EEA-9CFA-46A7ED9E2EE8} - C:\WINNT\system32\khjjpee.dll
O18 - Filter: text/plain - {9F76EA5E-A402-4EEA-9CFA-46A7ED9E2EE8} - C:\WINNT\system32\khjjpee.dll
O23 - Service: Sophos AutoUpdate Service (ActiveLinkClient) - Unknown owner - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Thanks
I have rerun SpseHjfix (disinfect) and CWShredder to get internet access back

Posting logs from then on :
Before and after SPSeHjFix logs
CWSshredder log
HJT log

(5/16/05 14:03:25) SPSeHjFix started v1.1.2
(5/16/05 14:03:25) OS: Win2000 Service Pack 4 (5.0.2195)
(5/16/05 14:03:25) Language: english
(5/16/05 14:03:25) Win-Path: C:\WINNT
(5/16/05 14:03:25) System-Path: C:\WINNT\system32
(5/16/05 14:03:25) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\


(5/16/05 16:51:00) SPSeHjFix started v1.1.2
(5/16/05 16:51:00) OS: Win2000 Service Pack 4 (5.0.2195)
(5/16/05 16:51:00) Language: english
(5/16/05 16:51:00) Win-Path: C:\WINNT
(5/16/05 16:51:00) System-Path: C:\WINNT\system32
(5/16/05 16:51:00) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(5/16/05 16:51:11) Disinfection started
(5/16/05 16:51:11) Bad-Dll(IEP): (not found)
(5/16/05 16:51:11) Bad-Dll(IEP) in BHO: (not found)
(5/16/05 16:51:11) UBF: 7 - UBB: 0 - UBR: 4
(5/16/05 16:51:11) UBF: 7 - UBB: 0 - UBR: 4
(5/16/05 16:51:11) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Default_Search_URL:
deleted: HKCU\Software\Microsoft\Internet Explorer, SearchURL:
(5/16/05 16:51:12) Stealth-String not found
(5/16/05 16:51:12) Not infected->END


(5/19/05 07:02:31) SPSeHjFix started v1.1.2
(5/19/05 07:02:31) OS: Win2000 Service Pack 4 (5.0.2195)
(5/19/05 07:02:31) Language: english
(5/19/05 07:02:31) Win-Path: C:\WINNT
(5/19/05 07:02:31) System-Path: C:\WINNT\system32
(5/19/05 07:02:31) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\


(5/19/05 12:10:28) SPSeHjFix started v1.1.2
(5/19/05 12:10:28) OS: Win2000 Service Pack 4 (5.0.2195)
(5/19/05 12:10:28) Language: english
(5/19/05 12:10:28) Win-Path: C:\WINNT
(5/19/05 12:10:28) System-Path: C:\WINNT\system32
(5/19/05 12:10:28) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(5/19/05 12:10:38) Disinfection started
(5/19/05 12:10:38) Bad-Dll(IEP): c:\docume~1\admini~1\locals~1\temp\se.dll
(5/19/05 12:10:38) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINNT\system32\khjjpee.dll
(5/19/05 12:10:38) Searchassistant Uninstaller - Keys Deleted
(5/19/05 12:10:38) UBF: 9 - UBB: 0 - UBR: 5
(5/19/05 12:10:38) FilterKey: HKCR\text/html (deleted)
(5/19/05 12:10:38) FilterKey: HKCR\CLSID\{9F76EA5E-A402-4EEA-9CFA-46A7ED9E2EE8} (deleted)
(5/19/05 12:10:38) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(5/19/05 12:10:38) FilterKey: HKCR\text/plain (deleted)
(5/19/05 12:10:38) FilterKey: HKCR\CLSID\{9F76EA5E-A402-4EEA-9CFA-46A7ED9E2EE8} (error while deleting)
(5/19/05 12:10:38) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(5/19/05 12:10:38) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE0DD88F-0A97-4C1D-902D-AEA47E605D79} (deleted)
(5/19/05 12:10:38) BHO-Key: HKCR\CLSID\{EE0DD88F-0A97-4C1D-902D-AEA47E605D79} (deleted)
(5/19/05 12:10:38) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\WINNT\TEMP\se.dll,DllInstall (deleted)
(5/19/05 12:10:38) UBF: 7 - UBB: 0 - UBR: 4
(5/19/05 12:10:38) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/sp.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\admini~1\locals~1\temp\se.dll/sp.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(5/19/05 12:10:39) Stealth-String not found
(5/19/05 12:10:39) File added to delete: c:\winnt\system32\khjjpee.dll
(5/19/05 12:10:39) File added to delete: c:\winnt\temp\se.dll
(5/19/05 12:10:39) Reboot

**** Run Keys ****

RUN: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
RUN: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
RUN: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
RUN: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
RUN: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe


**** Browser Helper Objects ****



**** IE Toolbars ****



**** IE Extensions ****



**** Hosts File Entries ****



**** IE Settings ****

IEProxy: SERVERW2K:8080
IEBypass:
Default Page: http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
Default Search: http://home.microsoft.com/search/search.asp
Local Page: C:\WINNT\system32\blank.htm


**** IE Context Menu (Right click) ****



**** Layered Service Providers ****

LSP: MSAFD Tcpip [TCP/IP]
LSP: MSAFD Tcpip [UDP/IP]
LSP: RSVP UDP Service Provider
LSP: RSVP TCP Service Provider
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}] SEQPACKET 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}] DATAGRAM 3
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2178334-F6A9-49BD-9B6A-B300EEAEA7C9}] SEQPACKET 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E2178334-F6A9-49BD-9B6A-B300EEAEA7C9}] DATAGRAM 0
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{144FC538-1EC2-4B98-8862-1FD1083E9FF9}] SEQPACKET 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{144FC538-1EC2-4B98-8862-1FD1083E9FF9}] DATAGRAM 1
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{09A25F65-2FDD-4984-8E1E-D06283D3E8DE}] SEQPACKET 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{09A25F65-2FDD-4984-8E1E-D06283D3E8DE}] DATAGRAM 2
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9B8CF85A-83C8-4F8A-A432-014E0EC310B9}] SEQPACKET 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{9B8CF85A-83C8-4F8A-A432-014E0EC310B9}] DATAGRAM 4
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{321BF937-A0B1-4CCE-BB99-5B989BFBAAA3}] SEQPACKET 5
LSP: MSAFD NetBIOS [\Device\NetBT_Tcpip_{321BF937-A0B1-4CCE-BB99-5B989BFBAAA3}] DATAGRAM 5


**** Blocked Control Panel Items ****

BLOCKED: [ncpa.cpl] No
BLOCKED: [odbccp32.cpl] No


**** Downloaded Program Files ****

DirectAnimation Java Classes [file://C:\WINNT\Java\classes\dajava.cab]
Microsoft XML Parser for Java [file://C:\WINNT\Java\classes\xmldso.cab]
{9A9307A0-7DA4-4DAF-B042-5009F29E09E1} [http://www.pandasoftware.com/activescan/as5/asinst.cab] C:\WINNT\Downloaded Program Files\asinst.dll
{CAFEEFAC-0012-0000-0000-ABCDEFFEDCBA} [http://java.sun.com/update/1.2.0/jinstall-1_2_0-windows-i586.cab]
{D27CDB6E-AE6D-11CF-96B8-444553540000} [http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab]
{EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} [http://lg.home.microsoft.com/search/lobby/searchsettings.cab]


**** Windows Services ****

[ActiveLinkClient] "C:\Program Files\Sophos\AutoUpdate\ALsvc.exe"
[Alerter] %SystemRoot%\System32\services.exe
[AppMgmt] %SystemRoot%\system32\services.exe
[aspnet_state] %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe
[BackupExecAgentAccelerator] "C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe"
[BackupExecAgentBrowser] "C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe"
[BackupExecDeviceMediaService] "C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe"
[BackupExecJobEngine] "C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe"
[BackupExecNamingService] "C:\Program Files\VERITAS\Backup Exec\NT\benser.exe"
[BackupExecRPCService] "C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe"
[BITS] %SystemRoot%\System32\svchost.exe -k BITSgroup
[Browser] %SystemRoot%\System32\services.exe
[cisvc] C:\WINNT\System32\cisvc.exe
[ClipSrv] %SystemRoot%\system32\clipsrv.exe
[Dfs] %SystemRoot%\system32\Dfssvc.exe
[Dhcp] %SystemRoot%\System32\services.exe
[DHCPServer] %SystemRoot%\System32\tcpsvcs.exe
[dmadmin] %SystemRoot%\System32\dmadmin.exe /com
[dmserver] %SystemRoot%\System32\services.exe
[DNS] %SystemRoot%\System32\dns.exe
[Dnscache] %SystemRoot%\System32\services.exe
[ECM Service] C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
[Eventlog] %SystemRoot%\system32\services.exe
[EventSystem] C:\WINNT\System32\svchost.exe -k netsvcs
[Fax] %systemroot%\system32\faxsvc.exe
[IISADMIN] C:\WINNT\System32\inetsrv\inetinfo.exe
[IMAP4Svc] C:\WINNT\System32\inetsrv\inetinfo.exe
[Iomega Activity Disk2] ""
[Iomega App Services] "C:\PROGRA~1\Iomega\System32\AppServices.exe"
[IsmServ] %SystemRoot%\System32\ismserv.exe
[kdc] %SystemRoot%\System32\lsass.exe
[lanmanserver] %SystemRoot%\System32\services.exe
[lanmanworkstation] %SystemRoot%\System32\services.exe
[LicenseService] %SystemRoot%\System32\llssrv.exe
[LmHosts] %SystemRoot%\System32\services.exe
[LMSessn] "F:\Program Files\Sophos\Control Center\LMSessn.exe"
[Messenger] %SystemRoot%\System32\services.exe
[MMRot] "F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe"
[mnmsrvc] C:\WINNT\System32\mnmsrvc.exe
[MSDTC] C:\WINNT\System32\msdtc.exe
[MSExchangeES] C:\Program Files\Exchsrvr\bin\events.exe
[MSExchangeIS] C:\Program Files\Exchsrvr\bin\store.exe
[MSExchangeMGMT] C:\Program Files\Exchsrvr\bin\exmgmt.exe
[MSExchangeMTA] C:\Program Files\Exchsrvr\bin\emsmta.exe
[MSExchangeSA] C:\Program Files\Exchsrvr\bin\mad.exe
[MSExchangeSRS] C:\Program Files\Exchsrvr\bin\srsmain.exe
[MSIServer] C:\WINNT\system32\msiexec.exe /V
[MSPOP3Connector] "C:\Program Files\Microsoft BackOffice\Connectivity\POP3 Connector\vmimb.exe" /SERVICE
[MSSEARCH] "C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe"
[MSSQL$BKUPEXEC] C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe -sBKUPEXEC
[MSSQL$SOPHOS] C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe -sSOPHOS
[MSSQLServerADHelper] C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe
[NetDDE] %SystemRoot%\system32\netdde.exe
[NetDDEdsdm] %SystemRoot%\system32\netdde.exe
[Netlogon] %SystemRoot%\System32\lsass.exe
[Netman] %SystemRoot%\System32\svchost.exe -k netsvcs
[NntpSvc] C:\WINNT\System32\inetsrv\inetinfo.exe
[NtFrs] %SystemRoot%\system32\ntfrs.exe
[NtLmSsp] %SystemRoot%\System32\lsass.exe
[NtmsSvc] %SystemRoot%\System32\svchost.exe -k netsvcs
[PlugPlay] %SystemRoot%\system32\services.exe
[PolicyAgent] %SystemRoot%\System32\lsass.exe
[POP3Svc] C:\WINNT\System32\inetsrv\inetinfo.exe
[ProtectedStorage] %SystemRoot%\system32\services.exe
[RasAuto] %SystemRoot%\System32\svchost.exe -k netsvcs
[RasMan] %SystemRoot%\System32\svchost.exe -k netsvcs
[RemoteAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[RemoteRegistry] %SystemRoot%\system32\regsvc.exe
[RESvc] C:\WINNT\System32\inetsrv\inetinfo.exe
[RpcLocator] %SystemRoot%\System32\locator.exe
[RpcSs] %SystemRoot%\system32\svchost -k rpcss
[RSVP] %SystemRoot%\System32\rsvp.exe -s
[SamSs] %SystemRoot%\system32\lsass.exe
[savexsrvc] "F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe"
[SCardDrv] %SystemRoot%\System32\SCardSvr.exe
[SCardSvr] %SystemRoot%\System32\SCardSvr.exe
[Schedule] %SystemRoot%\system32\MSTask.exe
[sdbnsrvc] "F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe"
[seclogon] %SystemRoot%\system32\services.exe
[SEMScheduler] "F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe"
[SENS] %SystemRoot%\system32\svchost.exe -k netsvcs
[SharedAccess] %SystemRoot%\System32\svchost.exe -k netsvcs
[SharedFax] C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
[SMTPSVC] C:\WINNT\System32\inetsrv\inetinfo.exe
[Sophos Agent] "F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent
[Sophos AutoUpdate Agent] "F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC
[Sophos Message Router] "F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router
[Sophos SBE Certification Manager] "F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf"
[Sophos SBE ManagementService] "F:\Program Files\Sophos\Control Center\SbeMss.exe"
[Spooler] %SystemRoot%\system32\spoolsv.exe
[SQLAgent$BKUPEXEC] C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlagent.EXE -i BKUPEXEC
[SQLAgent$SOPHOS] C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlagent.EXE -i SOPHOS
[SWEEPSRV.SYS] "C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS"
[SysmonLog] %SystemRoot%\system32\smlogsvc.exe
[TapiSrv] %SystemRoot%\System32\svchost.exe -k tapisrv
[TermService] %SystemRoot%\System32\termsrv.exe
[TlntSvr] %SystemRoot%\system32\tlntsvr.exe
[TrkSvr] %SystemRoot%\system32\services.exe
[TrkWks] %SystemRoot%\system32\services.exe
[UPS] %SystemRoot%\System32\ups.exe
[UtilMan] %SystemRoot%\System32\UtilMan.exe
[vsmon] C:\WINNT\system32\ZoneLabs\vsmon.exe -service
[W32Time] %SystemRoot%\System32\services.exe
[W3SVC] C:\WINNT\System32\inetsrv\inetinfo.exe
[WinMgmt] %SystemRoot%\System32\WBEM\WinMgmt.exe
[WINS] %SystemRoot%\System32\wins.exe
[Wmi] %SystemRoot%\system32\Services.exe
[wuauserv] %systemroot%\system32\svchost.exe -k wugroup
[WZCSVC] %SystemRoot%\System32\svchost.exe -k netsvcs


**** Custom IE Search Items ****

SEARCH: [CustomizeSearch] http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


**** Complete IE Options ****

IEOPT: [NoUpdateCheck]
IEOPT: [NoJITSetup]
IEOPT: [Disable Script Debugger] yes
IEOPT: [Show_ChannelBand] No
IEOPT: [Anchor Underline] yes
IEOPT: [Cache_Update_Frequency] Once_Per_Session
IEOPT: [Display Inline Images] yes
IEOPT: [Do404Search]
IEOPT: [Local Page] C:\WINNT\system32\blank.htm
IEOPT: [Save_Session_History_On_Exit] no
IEOPT: [Show_FullURL] no
IEOPT: [Show_StatusBar] yes
IEOPT: [Show_ToolBar] yes
IEOPT: [Show_URLinStatusBar] yes
IEOPT: [Show_URLToolBar] yes
IEOPT: [Use_DlgBox_Colors] yes
IEOPT: [Q261272] yes
IEOPT: [FullScreen] no
IEOPT: [Use FormSuggest] no
IEOPT: [Window_Placement] ,
IEOPT: [AddToFavoritesExpanded]
IEOPT: [NotifyDownloadComplete] yes
IEOPT: [FavChevron] NO
IEOPT: [HistoryViewType]
IEOPT: [HistoryTopNSitesView]
IEOPT: [Use Search Asst] no
IEOPT: [Error Dlg Displayed On Every Error] no
IEOPT: [Error Dlg Details Pane Open] no
IEOPT: [Toolbars_Placement] #(ŒB•§E· ‚éXH )„ÛxÿÿÿÿÿÿÿÿJ
IEOPT: [Use Custom Search URL]
IEOPT: [Check_Associations] yes
IEOPT: [Expand Alt Text] no
IEOPT: [Move System Caret] no
IEOPT: [NscSingleExpand]
IEOPT: [Page_Transitions]
IEOPT: [FavIntelliMenus] yes
IEOPT: [AllowWindowReuse]
IEOPT: [Friendly http errors] yes
IEOPT: [ShowGoButton] yes
IEOPT: [SmoothScroll]
IEOPT: [Play_Animations] yes
IEOPT: [Play_Background_Sounds] yes
IEOPT: [Display Inline Videos] yes
IEOPT: [Show image placeholders]
IEOPT: [Print_Background] no
IEOPT: [LastCheckedHi]
IEOPT: [FormSuggest PW Ask] no
IEOPT: [Enable_Disk_Cache] yes
IEOPT: [Cache_Percent_of_Disk]
IEOPT: [Delete_Temp_Files_On_Exit] yes
IEOPT: [Local Page] C:\WINNT\system32\blank.htm
IEOPT: [Anchor_Visitation_Horizon]
IEOPT: [Use_Async_DNS] yes
IEOPT: [Placeholder_Width]
IEOPT: [Placeholder_Height]
IEOPT: [CompanyName] Microsoft Corporation
IEOPT: [Custom_Key] MICROSO
IEOPT: [Wizard_Version] 6.00.2800.1106
IEOPT: [FullScreen] no
IEOPT: [Check_Associations] yes
IEOPT: [Default_Page_URL] http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
IEOPT: [Default_Search_URL] http://home.microsoft.com/search/search.asp
IEOPT: [Use Search Asst] no
IEOPT: [Use Custom Search URL]



(5/19/05 12:31:31) SPSeHjFix started v1.1.2
(5/19/05 12:31:31) OS: Win2000 Service Pack 4 (5.0.2195)
(5/19/05 12:31:31) Language: english
(5/19/05 12:31:31) Win-Path: C:\WINNT
(5/19/05 12:31:31) System-Path: C:\WINNT\system32
(5/19/05 12:31:31) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\


(5/19/05 12:32:15) SPSeHjFix started v1.1.2
(5/19/05 12:32:15) OS: Win2000 Service Pack 4 (5.0.2195)
(5/19/05 12:32:15) Language: english
(5/19/05 12:32:15) Win-Path: C:\WINNT
(5/19/05 12:32:15) System-Path: C:\WINNT\system32
(5/19/05 12:32:15) Temp-Path: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\
(5/19/05 12:32:20) Disinfection started
(5/19/05 12:32:20) Bad-Dll(IEP): (not found)
(5/19/05 12:32:20) Bad-Dll(IEP) in BHO: (not found)
(5/19/05 12:32:20) UBF: 7 - UBB: 0 - UBR: 5
(5/19/05 12:32:20) UBF: 7 - UBB: 0 - UBR: 5
(5/19/05 12:32:20) Bad IE-pages: (none)
(5/19/05 12:32:20) Stealth-String found: C:\WINNT\System32\d3dc.dll
(5/19/05 12:32:20) Error while add to delete. Try another way… : C:\WINNT\System32\d3dc.dll
(5/19/05 12:32:20) No locked Files to delete. End without Reboot
(5/19/05 12:32:40) Disinfection started
(5/19/05 12:32:40) Bad-Dll(IEP): (not found)
(5/19/05 12:32:40) Bad-Dll(IEP) in BHO: (not found)
(5/19/05 12:32:40) UBF: 7 - UBB: 0 - UBR: 5
(5/19/05 12:32:40) UBF: 7 - UBB: 0 - UBR: 5
(5/19/05 12:32:40) Bad IE-pages: (none)
(5/19/05 12:32:40) Stealth-String not found
(5/19/05 12:32:40) Not infected->END

Logfile of HijackThis v1.99.1
Scan saved at 12:48:46, on 19/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
F:\Program Files\Sophos\Remote Management System\ALCAgent.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\TEMP\sotmp1.dir\ALUpdate.exe
C:\Program Files\Sophos\AutoUpdate\almon.exe
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
F:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
F:\HJT\HijackThis.exe
C:\WINNT\TEMP\Sophos\Setup\Loader\setup.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O23 - Service: Sophos AutoUpdate Service (ActiveLinkClient) - Unknown owner - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Cheers
Scan with hijackthis and put a check beside these lines and choose FIX R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Then reboot to normal mode and post a new log please.
Good Morning - Checked the following 2 lines

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

New Log

Logfile of HijackThis v1.99.1
Scan saved at 06:50:14, on 20/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
F:\Program Files\Sophos\Remote Management System\ALCAgent.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\Explorer.EXE
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
F:\Program Files\ZoneAlarm\zlclient.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [Zone Labs Client] "F:\Program Files\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe

Thanks
Hi Siggyx - 2 Logs from this morning

1) HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 06:25:24, on 23/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
F:\Program Files\Sophos\Remote Management System\ALCAgent.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\Explorer.EXE
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\dmadmin.exe
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe


2) Microsoft Antispyware (Beta 1)

Spyware Scan Details
Start Date: 23/05/2005 02:00:17
End Date: 23/05/2005 02:13:46
Total Time: 13 mins 29 secs

Detected Threats

SearchAssistant Spyware more information…
Details: SearchAssistant also known as Search Extender is an Internet Explorer modifier.
Status: Ignored
Severe threat - Severe-risk items have an extreme potential for harm, such as a security exploit, and should be removed.

Infected files detected
c:\documents and settings\administrator\local settings\temp\se.dll


Possible Browser Hijack Browser Modifier more information…
Details: This spyware threat changes Web browser settings, such as the homepage, without adequate consent.
Status: Ignored
High threat - High-risk items have a large potential for harm, such as loss of computer control, and should be removed unless knowingly installed.


RealVNC Remote Control Software more information…
Details: RealVNC (Virtual Network Computing) allows a computer to view and interact with any other computer or mobile device on the Internet.
Status: Ignored
Moderate threat - Moderate-risk items have some potential for harm, but may be part of a wanted service. Users may decide to ignore such programs after review.

Infected registry keys/values detected
HKEY_LOCAL_MACHINE\Software\ORL
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3 DebugMode 0
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3 DebugLevel 0
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3 AllowLoopback 0
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3 MSLogonRequired 0
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3 UseDSMPlugin 0
HKEY_LOCAL_MACHINE\Software\ORL\WinVNC3


Detected Spyware Cookies
No spyware cookies were found during this scan.

N.B. Have taken off Zonealarm for now

Cheers
Good Morning Siggyx

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 06:42:27, on 27/05/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\termsrv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\msdtc.exe
C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
C:\WINNT\system32\Dfssvc.exe
C:\WINNT\System32\tcpsvcs.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINNT\System32\ismserv.exe
C:\WINNT\System32\llssrv.exe
F:\Program Files\Sophos\Control Center\LMSessn.exe
F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
C:\Program Files\Microsoft SQL Server\MSSQL$BKUPEXEC\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SOPHOS\Binn\sqlservr.exe
C:\WINNT\system32\ntfrs.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\System32\locator.exe
C:\WINNT\system32\MSTask.exe
F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe
F:\Program Files\Sophos\Control Center\SbeMss.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\wins.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dns.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\Program Files\Microsoft Shared Fax\Bin\FXSSVC.exe
C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\Program Files\Exchsrvr\bin\emsmta.exe
C:\WINNT\Explorer.EXE
C:\Program Files\USB Disk Tool\USNDISKT.EXE
C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\dmadmin.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\AutoUpdate\almon.exe
F:\Program Files\Sophos\Remote Management System\RouterNT.exe
F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
F:\Program Files\Sophos\Remote Management System\ALCAgent.exe
F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
C:\WINNT\System32\mdm.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS
C:\Program Files\Internet Explorer\IEXPLORE.EXE
F:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = SERVERW2K:8080
O4 - HKLM\..\Run: [USB Disk Tool] C:\Program Files\USB Disk Tool\USNDISKT.EXE
O4 - HKLM\..\Run: [VxTaskbarMgr] C:\Program Files\VERITAS\VxUpdate\VxTaskbarMgr.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [Iomega Automatic Backup] C:\Program Files\Iomega\Iomega Automatic Backup\ibackup.exe
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {EE8B6D5F-FEF2-11D0-B13F-00A024798EF3} (Microsoft Search Settings Control) - http://lg.home.microsoft.com/search/lobby/searchsettings.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{775ED3E8-DC7B-4665-8E70-00F2BB67AA05}: NameServer = 10.0.0.2,217.149.108.10
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = beaublack.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = beaublack.local
O23 - Service: Sophos AutoUpdate Service (ActiveLinkClient) - Unknown owner - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Backup Exec Remote Agent for Windows Servers (BackupExecAgentAccelerator) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beremote.exe
O23 - Service: Backup Exec Agent Browser (BackupExecAgentBrowser) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benetns.exe
O23 - Service: Backup Exec Device & Media Service (BackupExecDeviceMediaService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\pvlsvr.exe
O23 - Service: Backup Exec Job Engine (BackupExecJobEngine) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\bengine.exe
O23 - Service: Backup Exec Naming Service (BackupExecNamingService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\benser.exe
O23 - Service: Backup Exec Server (BackupExecRPCService) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\beserver.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ExecView Communication Module (ECM) (ECM Service) - VERITAS Software Corporation - C:\Program Files\VERITAS\Backup Exec\NT\ECM\ECM.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Sophos Session Manager (LMSessn) - TODO: - F:\Program Files\Sophos\Control Center\LMSessn.exe
O23 - Service: PureMessage Running Object Table (MMRot) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\mmrot2.exe
O23 - Service: PureMessage Service (savexsrvc) - Sophos Plc - F:\Program Files\Sophos\PureMessage\bin\savexsrvc.exe
O23 - Service: Sophos Database Notification Service (sdbnsrvc) - Sophos Plc - F:\Program Files\Sophos\Control Center\Sdbnsrvc.exe
O23 - Service: Sophos Enterprise Manager Scheduler (SEMScheduler) - Unknown owner - F:\Program Files\Sophos\Control Center\Library\bin\SchdSrvc.exe
O23 - Service: Sophos Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe" -service -name Agent (file missing)
O23 - Service: Sophos AutoUpdate Agent - Unknown owner - F:\Program Files\Sophos\Remote Management System\ALCAgent.exe" -service -name ALC (file missing)
O23 - Service: Sophos Message Router - Unknown owner - F:\Program Files\Sophos\Remote Management System\RouterNT.exe" -service -name Router (file missing)
O23 - Service: Sophos SBE Certification Manager - Unknown owner - F:\Program Files\Sophos\Control Center\CertificationManagerServiceNT.exe" -background -ORBSvcConf "F:\Program Files\Sophos\Control Center\svc.conf (file missing)
O23 - Service: Sophos SBE ManagementService - Sophos Plc - F:\Program Files\Sophos\Control Center\SbeMss.exe
O23 - Service: Sophos Anti-Virus (SWEEPSRV.SYS) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SWEEPSRV.SYS

Anything Nasty ? 2 Days ago Sophos picked up and destroyed Trojan 'Ablank S' saying it was proliferating in Registry Keys i.e. Internet Explorer Main Search and Uninstall Keys. Microsoft Antispyware has not found anything since. Cheers.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI