This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PROBLEM WITH HIJACK THIS

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

:rant2:
I have SPYSWEEPER (webroot) & Panda AntiVirus but have a problem that I can't get rid of.

WEBROOT folks told me to get rid of these files in safe mode
Intmon.exe
Intmonp.exe
Msole.exe
Popuper.exe

Then ran HIJACKThis and got rid of several R1's and a BHO, but after rebooting in normal mode the items in HIJACK THIS are back (see log) and the Intmon.exe is back (the other exe files are gone!).

Any suggestions…When I'm in IE my searches get HIJACKED by Quicknavigate I've spent hours trying to fix this but can't get my hands around this one.

Logfile of HijackThis v1.99.1
Scan saved at 1:26:23 PM, on 5/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\apvxdwin.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\shnlog.exe
C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\lsas.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\System32\sessmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\intmon.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Robert\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.quicknavigate.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.quicknavigate.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.quicknavigate.com/
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} - C:\WINDOWS\System32\hpF099.tmp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AS00_Netgear] C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Shellspl] lsas.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
Hi and welcome to the forum. :D

Step # 1

Please download and run CWShredder. Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.

http://www.majorgeeks.com/downloadget.php?…7fd6b3ff02edc90

REBOOT

Step #2

Please download and run Spybot & AdAware SE Then follow the instructions in the link below to run.

Spybot & Adaware Tutorial

REBOOT

Step # 3

Then do 2 virus scans here >>>

Trend Micro

Panda

Reboot and post a new HiJackThis log.
:( :(

Thanks for the suggestions…. I ran CW Shredder / Rebooted / Ran SpyBot and Adware SE / Rebooted / Ran Micro Trend Virus Scan

But Could not Run the PANDA SCAN from the Live Scan Web Site of Panda….I was taken over by QuickNaviagte (Again!!)

I did a HJ log after rebooting….here it is!

Logfile of HijackThis v1.99.1
Scan saved at 6:22:16 PM, on 5/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\shnlog.exe
C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\lsas.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\WINDOWS\System32\sessmgr.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\intmon.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Robert\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.quicknavigate.com/bar.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.quicknavigate.com/search.php?qq=%1
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.quicknavigate.com/search.php?qq=%1
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.quicknavigate.com/
O2 - BHO: VMHomepage Class - {FFFFFFFF-FFFF-FFFF-FFFF-FFFFFFFFFFFF} - C:\WINDOWS\System32\hp7280.tmp
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AS00_Netgear] C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Shellspl] lsas.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
Please read these instructions carefully and print them out! Be sure to follow ALL instructions!

Please right-click: HERE and go to Save As (in Internet Explorer it's "Save Target As") in order to download Grinler's reg file. Save it to your desktop.

Locate "smitfraud.reg" on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the "merged successfully" prompt then follow the rest of the instructions below.

Go to Start > Control Panel > Add or Remove Programs and remove the following programs, if found:

Security IGuard
Virtual Maid
Search Maid


Exit Add/Remove Programs.

*IMPORTANT*CLICK THIS LINK TO LEARN HOW TO VIEW HIDDEN FILES

I need you to copy all of the Killbox file paths below and paste them into Notepad.

* Please download the Killbox by Option^Explicit. *In the event you already have Killbox, this is a new version that I need you to download.

* Save it to your desktop.

* Please double-click Killbox.exe to run it.

* Select "Delete on Reboot".

* Open the Notepad file where you saved the file paths earlier and copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C

C:\wp.exe
C:\wp.bmp
C:\bsw.exe
C:\Windows\sites.ini
C:\Windows\popuper.exe
C:\Windows\System32\wldr.dll
C:\Windows\System32\helper.exe
C:\Windows\System32\intmon.exe
C:\Windows\System32\shnlog.exe
C:\Windows\System32\intmonp.exe
C:\Windows\System32\msmsgs.exe
C:\Windows\system32\msole32.exe
C:\Windows\System32\ole32vbs.exe


* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

While your computer is restarting, tap the F8 key continually until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Make sure you can view hidden files.

Using Windows Explorer, delete the following, if found, (please do NOT try to find them by "search" because they will not show up that way)

FOLDERS to delete (in bold) if found:

C:\Program Files\Search Maid
C:\Program Files\Virtual Maid
C:\Windows\System32\Log Files
C:\Program Files\Security IGuard

While still in Safe Mode, do the following:

Make sure all programs and windows are closed. Run HiJackThis and place a check next to the following items, if found, then click FIX CHECKED

items to fix

Close HiJackThis.

Reboot into normal mode.

1.) Download The Hoster Press "Restore Original Hosts" and press "OK". Exit Program.

2.) Right-Click HERE and Save As to download DelDomains.inf to your desktop.
To use: RIGHT-CLICK DelDomains.inf on your desktop and select: Install (no need to restart)
Note: This will remove all entries in the "Trusted Zone" and "Ranges" also.

3.) Download, install, and run CleanUp!

4.) Run this online virus scan: ActiveScan - Save the results from the scan!

Post a new HiJackThis log along with the results from ActiveScan.
:) :)

This looks much, much better!! That took a long time, but it seems to have worked! ActiveScan by Panda recognized 23 items, but did not disenfect them. I have PANDA Ver 7.0 (bought in Oct 04), but I never picked up those items before. Do I need to buy a different version of PANDA …I have Platinum, but they don't post that now…it is TITANIUM or BETTER.

Attached are my ACTIVE SCAN log files and the HIJACKTHIS Logs.

Seems to have been fixed. I'm gonna reboot and see if all continues WELL!!

Logfile of HijackThis v1.99.1
Scan saved at 9:57:34 PM, on 5/14/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\lsas.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
C:\WINDOWS\System32\sessmgr.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
C:\Documents and Settings\Robert\Desktop\hijackthis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AS00_Netgear] C:\Program Files\NETGEAR\Wireless Smart Configuration\Utility\NetgearAG.exe -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Shellspl] lsas.exe
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O4 - Global Startup: Palo Alto Software Update Manager 8.0.lnk = C:\Program Files\Common Files\Palo Alto Software\8.0\PAS8_Update.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda Software - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)

ACTIVE SCAN LOG


Incident Status Location

Spyware:Spyware/Searchcentrix No disinfected Windows Registry
Adware:Adware/ILookup No disinfected C:\Documents and Settings\Robert\Favorites\Gambling
Adware:Adware/STIEBar No disinfected C:\Program Files\STHomePage
Adware:Adware/Virmaid No disinfected C:\WINDOWS\System32\perfcii.ini
Adware:Adware/Popuper No disinfected C:\backup-20050512-054359-849.dll
Adware:Adware/Popuper No disinfected C:\backup-20050512-055433-810.dll
Adware:Adware/Popuper No disinfected C:\backup-20050512-065757-728.dll
Adware:Adware/Popuper No disinfected C:\backup-20050512-183141-438.dll
Adware:Adware/Popuper No disinfected C:\backup-20050512-184630-592.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-001352-485.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-083039-935.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-085202-732.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-085217-822.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-085822-237.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-100951-940.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-102359-492.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-113724-441.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-120724-704.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-135956-426.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-152559-384.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-183040-318.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-183158-239.dll
Adware:Adware/Popuper No disinfected C:\Documents and Settings\Robert\Desktop\hijackthis\backups\backup-20050514-204746-890.dll
Adware:Adware/SearchAid No disinfected C:\WINDOWS\sdkkv.dll
Adware:Adware/Popuper No disinfected C:\WINDOWS\system32\hhk.dll
Adware:Adware/Virmaid No disinfected C:\WINDOWS\system32\perfcii.ini
SHOULD I RE-RUN MY OWN PANDA VIRUS SCAN AND SEE IF IT PICKS UP THESE SAME THINGS? FOR SOME REASON I DON'T THINK IT WILL, BUT NOT SURE WHY NOT!

THANKS

:rofl:
Scan with hijackthis and put a check beside this lines and choose FIX O4 - HKLM\..\Run: [Shellspl] lsas.exe Then boot to safe moe and look for and delete these files C:\WINDOWS\sdkkv.dll C:\WINDOWS\system32\hhk.dll C:\WINDOWS\system32\perfcii.ini lsas.exe Then reboot and post a new hijackthis log.
<_< NEW PROBLEM?? I ran HIJACKTHIS and fixed 04 - HKLM\..\Run [Shellsp] Isas.exe But when I tried to reboot in SafeMode the system locked up each time (in safe mode) I tried to sign in to my user. I then rebooted and logged on in 'reg' mode, but I didn't try to delete the other files you recommended, because I'm not sure what is going on now.
Download MicroWorld virus scan here >>> Micro World http://www.mwti.net/antivirus/free_utilities.asp

To run the virus scan make sure you click the following

memory, registry, startup folders, system folders, services, drive (all drives will be added) then click on scan clean. When the scan is complete hilight all the files in the LOWER box. Then ctrl + c and paste them into the thread ctrl + v.

I warn you the scan will take a long time to run and will not fix anything just identifies bad files.
I ran the Micro World Virus Scan…WOW… I had just ran PANDA 15 minutes before getting your email on this and had nothing….. WOW this is unreal! File System Found infected by "Quicken Spyware/Adware" Virus. Action Taken: No Action Taken. File C:\WINDOWS\adv11.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\WINDOWS\blank.htm infected by "Trojan.Win32.StartPage.ro" Virus. Action Taken: No Action Taken. File C:\WINDOWS\botik.exe infected by "Trojan-Dropper.Win32.Agent.kk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\pumba.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\pumba2.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\adv11.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\beem.dll infected by "Trojan.Win32.StartPage.um" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\csrss.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\iasadm.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\lsas.exe infected by "Trojan-Dropper.Win32.Agent.kk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\systems32.exe infected by "not-a-virus:AdWare.Giga" Virus. Action Taken: No Action Taken. File C:\882cba94.hta infected by "Trojan-Downloader.VBS.Psyme.av" Virus. Action Taken: No Action Taken. File C:\backup-20050506-114551-208.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.d" Virus. Action Taken: No Action Taken. File C:\delibest\MASTER CARTON\Quick Pallet Maker\QPMWin_En.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\Program Files\STHomePage\uninst.exe infected by "not-a-virus:AdWare.MetaSearch.a" Virus. Action Taken: No Action Taken. File C:\Program Files\STLinks\uninst.exe infected by "not-a-virus:AdWare.MetaSearch.a" Virus. Action Taken: No Action Taken. File C:\Program Files\Worth Data\LabelRIGHT 3\Convert Utility Installer\Install.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033702.dll infected by "Trojan.Win32.StartPage.um" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033712.dll infected by "not-a-virus:AdWare.ToolBar.STIEBar.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033713.dll infected by "not-a-virus:AdWare.MetaSearch.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033714.dll infected by "not-a-virus:AdWare.MetaSearch.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033715.hta infected by "Trojan-Downloader.VBS.Psyme.av" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033716.dll infected by "not-a-virus:AdWare.ToolBar.STIEBar.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033717.dll infected by "not-a-virus:AdWare.MetaSearch.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP306\A0033718.dll infected by "not-a-virus:AdWare.ToolBar.STIEBar.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP342\A0036274.dll infected by "Trojan.Win32.Agent.q" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP352\A0036520.exe infected by "Trojan-Downloader.Win32.Small.aru" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP361\A0036781.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP361\A0036797.exe infected by "Trojan-Dropper.Win32.Small.oy" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP362\A0036872.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP365\A0036947.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP366\A0037049.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP366\A0037060.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP366\A0037087.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP367\A0037146.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.c" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP368\A0037160.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP368\A0037176.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP371\A0038088.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP372\A0038119.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP373\A0038131.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP374\A0038145.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP375\A0038177.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP375\A0039117.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP376\A0039154.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP376\A0039162.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP377\A0039190.exe infected by "Trojan-Downloader.Win32.Small.rr" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039192.exe infected by "Trojan-Dropper.Win32.Small.oy" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039196.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039206.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039211.dll infected by "not-a-virus:AdWare.ToolBar.MaidBar.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039213.dll infected by "Trojan-Downloader.Win32.Small.rr" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039246.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039252.exe infected by "Trojan-Downloader.Win32.Zlob.i" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039267.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP378\A0039279.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039649.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039659.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039822.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039832.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039861.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039889.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039915.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039926.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039937.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039952.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039972.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP392\A0039984.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040007.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040023.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040034.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040048.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040058.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040074.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040085.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040099.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040131.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP393\A0040146.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP394\A0040168.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP394\A0040176.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP394\A0040187.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP395\A0040344.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP395\A0040355.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP395\A0040373.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{C5F4D3E3-1CDA-4799-A1BE-35CE993CF849}\RP395\A0040393.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\WINDOWS\adv11.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\WINDOWS\blank.htm infected by "Trojan.Win32.StartPage.ro" Virus. Action Taken: No Action Taken. File C:\WINDOWS\botik.exe infected by "Trojan-Dropper.Win32.Agent.kk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\on-line.exe infected by "Trojan.Win32.Dialer.ce" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\on-line.exe infected by "Trojan.Win32.Dialer.ce" Virus. Action Taken: No Action Taken. File C:\WINDOWS\pumba.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\pumba2.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\adv11.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\beem.dll infected by "Trojan.Win32.StartPage.um" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\csrss.dll infected by "Trojan-Proxy.Win32.Small.bv" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\iasadm.dll infected by "not-a-virus:AdWare.ToolBar.Azesearch.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\lsas.exe infected by "Trojan-Dropper.Win32.Agent.kk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\systems32.exe infected by "not-a-virus:AdWare.Giga" Virus. Action Taken: No Action Taken.
Not as bad as it looks as most of those are sitting in your system restore which we will clean out when we are all finished. Boot to safe mode (tap f8 while bios loads) then look for and delete these files File C:\WINDOWS\botik.exe File C:\WINDOWS\pumba.dll File C:\WINDOWS\pumba2.dll File C:\WINDOWS\System32\adv11.exe File C:\WINDOWS\System32\beem.dll File C:\WINDOWS\System32\csrss.dll File C:\WINDOWS\System32\iasadm.dll File C:\WINDOWS\System32\lsas.exe . File C:\WINDOWS\System32\systems32.exe File C:\882cba94.hta Then reboot and post a new log please.
I tried to log on in SAFE MODE but it came up with the following error… File missing or damaged….. windows\system32\ntoskenl.exe it kicked me out of safe mode into reg mode and then I looked for the file. I did see it when I did the search….. should I copy the file off of another computer onto this computer????? it has a different date on it….9/3/2002 The one on this computer shows 3/1/2005…also there was a lot of other files with the same name….looking like some Windows updates…SP1 SP2 (?) I didn't retry to go back to SAFE MODE waiting for your comments.
Lets use windows sfc (system file checker) You'd need your XP CD to make this work. Click Start> Run> type sfc /scannow (Note that there is a space between sfc and /scannow) This will repair any bad windows files
:)

Ok I was able to get the SAFE MODE to work! I deleted the files you asked for in your previous post. I did find the csrss.dll had 2 other csrss application files (I deleted those also…I hope that was OK ???) the file 882cba94 was an application file and not a hta file. I deleted it also.

here is my HJ log file:

Logfile of HijackThis v1.99.1
Scan saved at 3:27:23 PM, on 5/16/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common

Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Panda Software\Panda Antivirus

Platinum\Firewall\PavFires.exe
C:\Program Files\Panda Software\Panda Antivirus

Platinum\pavsrv51.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Panda Software\Panda Antivirus

Platinum\AVENGINE.EXE
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Panda Software\Panda Antivirus

Platinum\apvxdwin.exe
C:\Program Files\NETGEAR\Wireless Smart

Configuration\Utility\NetgearAG.exe
C:\Program Files\Roxio\Easy CD Creator

5\DirectCD\DirectCD.exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
C:\Program Files\Common Files\Palo Alto

Software\8.0\PAS8_Update.exe
C:\Program Files\Common

Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Panda Software\Panda Antivirus

Platinum\pavProxy.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and

Settings\Robert\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start

Page = http://www.cnn.com
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE

C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AS00_Netgear] C:\Program

Files\NETGEAR\Wireless Smart

Configuration\Utility\NetgearAG.exe -hide
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program

Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common

Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program

Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda

Software\Panda Antivirus Platinum\Inicio.exe"
O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda

Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
O4 - HKCU\..\Run: [Window Washer] C:\Program

Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN

Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpySweeper] "C:\Program

Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - Startup: HotSync Manager.lnk = C:\Program

Files\Palm\HOTSYNC.EXE
O4 - Global Startup: NETGEAR WG311v2 Smart

Configuration.lnk = C:\Program Files\NETGEAR WG311v2

Adapter\wlancfg5.exe
O4 - Global Startup: Palo Alto Software Update Manager

8.0.lnk = C:\Program Files\Common Files\Palo Alto

Software\8.0\PAS8_Update.exe
O4 - Global Startup: QuickBooks Update Agent.lnk =

C:\Program Files\Common

Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program

Files\WinZip\WZQKPICK.EXE
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61}

(HouseCall Control) -

http://a840.g.akamai.net/7/840/537/2004061…housecall.trend

micro.com/housecall/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}

(ActiveScan Installer Class) -

http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: EPSON Printer Status Agent2

(EPSONStatusAgent2) - SEIKO EPSON CORPORATION -

C:\Program Files\Common

Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: Kodak Camera Connection Software

(KodakCCS) - Eastman Kodak Company -

C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) -

NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Panda Firewall Service (PAVFIRES) - Panda

Software - C:\Program Files\Panda Software\Panda Antivirus

Platinum\Firewall\PavFires.exe
O23 - Service: Panda anti-virus service (PAVSRV) - Panda

Software - C:\Program Files\Panda Software\Panda Antivirus

Platinum\pavsrv51.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) -

Unknown owner - C:\Program Files\Common Files\Symantec

Shared\SNDSrvc.exe (file missing)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI