This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

CWS INFESTATION?

37 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am not sure what to suggest for the excel problem as I don't really have any training to deal with that. Can you scan again with Ewido and see if it scans clean now?
Still a few things in there. ——————————————————— ewido security suite - Scan report ——————————————————— + Created on: 18:57:38, 02/10/2005 + Report-Checksum: 238C819F + Scan result: HKLM\SOFTWARE\Classes\CLSID\{676575DD-4D46-911D-8037-9B10D6EE8BB5} -> Spyware.CoolWebSearch : Cleaned with backup C:\WINNT\zzovgd.dat -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINNT\mfcor32.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINNT\movzec.dat -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINNT\wvrtxz.dat -> TrojanDownloader.Agent.bq : Cleaned with backup C:\WINNT\sbuow.dll -> Spyware.SearchPage : Cleaned with backup C:\WINNT\jdsiux.dat -> Spyware.SearchPage : Cleaned with backup C:\RECYCLED\Dc11.exe -> TrojanDownloader.Agent.bq : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@adtech[2].txt -> Spyware.Cookie.Adtech : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup C:\Documents and Settings\leo.quigley\Cookies\leo.quigley@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.12:C:\Documents and Settings\leo.quigley\Application Data\Mozilla\Firefox\Profiles\a68jigwk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.13:C:\Documents and Settings\leo.quigley\Application Data\Mozilla\Firefox\Profiles\a68jigwk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.14:C:\Documents and Settings\leo.quigley\Application Data\Mozilla\Firefox\Profiles\a68jigwk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.15:C:\Documents and Settings\leo.quigley\Application Data\Mozilla\Firefox\Profiles\a68jigwk.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup ::Report End
Ok, good job. Please download the free MWAV antivirus tool from here. Save it to the desktop and run it. Follow the prompts to scan your system for viruses. Then please post for me the log of infected files from the BOTTOM panel of the scan window. Please remove any lines relating to "Invalid object" as they are not needed at this time.
Slight problem with the download lnk but I managed to find another one. Here is the log: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\WINNT\iezm32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "vx2 Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "weathercast Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.homesearch Browser Hijacker" found in File System! Action Taken: No Action Taken. Object "ipinsight Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "netpal Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Shared Tools\osa.exe" refers to invalid object "C:\Program Files\Microsoft Office\Office\OSA.EXE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "HSA". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SE". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "SW". Action Taken: No Action Taken. Entry "HKCR\CLSID\{882598D7-86A2-FD56-4248-3DBB07E35EBB}" refers to invalid object "C:\WINNT\sysoz.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{AAC1083C-C6A6-9029-66F2-9CF7AF3E70B3}" refers to invalid object "C:\WINNT\ipey.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E1C1B11B-E049-47BB-A0A9-8004FF5CB831}" refers to invalid object "C:\WINNT\System32\MatAdown.dll". Action Taken: No Action Taken. Entry "HKCR\.aw" refers to invalid object "AWFile". Action Taken: No Action Taken. Entry "HKCR\.col" refers to invalid object "COLFile". Action Taken: No Action Taken. Entry "HKCR\.det" refers to invalid object "DETFile". Action Taken: No Action Taken. Entry "HKCR\.elm" refers to invalid object "ELMFile". Action Taken: No Action Taken. Entry "HKCR\.ffa" refers to invalid object "FFAFile". Action Taken: No Action Taken. Entry "HKCR\.ffl" refers to invalid object "FFLFile". Action Taken: No Action Taken. Entry "HKCR\.fft" refers to invalid object "FFTFile". Action Taken: No Action Taken. Entry "HKCR\.ffx" refers to invalid object "FFXFile". Action Taken: No Action Taken. Entry "HKCR\.frg" refers to invalid object "Access.Fragment". Action Taken: No Action Taken. Entry "HKCR\.ldb" refers to invalid object "Access.LockFile.9". Action Taken: No Action Taken. Entry "HKCR\.lex" refers to invalid object "LEXFile". Action Taken: No Action Taken. Entry "HKCR\.opc" refers to invalid object "OPCFile". Action Taken: No Action Taken. Entry "HKCR\.rfa" refers to invalid object "RadioFreeVirgin". Action Taken: No Action Taken. Entry "HKCR\.rfp" refers to invalid object "RadioFreeVirgin". Action Taken: No Action Taken. Entry "HKCR\.rfs" refers to invalid object "RadioFreeVirgin". Action Taken: No Action Taken. Entry "HKCR\.sll" refers to invalid object "SSLFile". Action Taken: No Action Taken. Entry "HKCR\.stf" refers to invalid object "STFFile". Action Taken: No Action Taken. Entry "HKCR\.tuw" refers to invalid object "TUWFile". Action Taken: No Action Taken. Entry "HKCR\.wll" refers to invalid object "Word.Addin.8". Action Taken: No Action Taken. File C:\WINNT\nvbjyf.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ysqjly.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ylvlnc.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\yoeztw.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\tncmcs.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\dljihs.txt infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\applc32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\javamk32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\threaz.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\vwtpzx.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\leudgz.log infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\veennk.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\sfgdtr.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\xzntvs.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\yrsnxw.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\vpyjkb.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\wizjfr.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\xbfmpu.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\osxepl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\xkfdzq.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\lucvsh.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\wjwtgl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\jldgwb.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\okcgzo.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ofpdai.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\sdusmb.log infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\wprppn.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\aapfdh.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\dvzodp.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\tylxdu.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\sdkmg.exe infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\WINNT\clabqn.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\vwhwka.log infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\vxqqky.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\znkpuz.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\meppdk.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\agpred.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\rokanb.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\fkywan.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\gddykq.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\hnvnbe.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\cllilv.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\dercvy.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\syqdqe.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\iruvtp.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\bbapws.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\boioek.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\cqplra.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\hzosyo.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ikumjs.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\cbufte.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\xjgjur.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\xcldwu.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\najwmi.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\otoqwl.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\swayaz.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\sgfakd.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ntnvwa.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\odaphd.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ydtaxl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\fwfcen.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\gpkxgr.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\zogdio.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\eoxjfj.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\fycdpm.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\nmqijj.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\kdcjsr.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\loqdcu.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\nfwclm.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ndvgzi.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\gvaacl.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\umjhlj.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\vfpbvm.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\qjwvhj.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\qccqkm.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ppvvbq.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\qibxmt.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\pnaxoa.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\iyfzyd.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\lknuka.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\dvsond.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\xflsbo.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\gpvowx.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\giaiza.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\yqquer.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\sksnnl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\tcypyo.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ohfkkl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\pzlemp.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\fxjxbc.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\xqwrmg.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\elxuvh.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\yytpce.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\lkisig.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\muousj.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\vsituv.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\hjrnsw.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ibwhcz.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\wlnvfy.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\zkcfxd.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\auhhhg.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\eyjwza.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\zvesva.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\agjnyd.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\wklhwa.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\pdybye.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\talyve.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\pxynre.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\hidhuh.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\hvrnxl.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\aowpzo.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\surdrq.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\seextt.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\mtxmoh.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\nldoqk.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\yojtzv.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ygowcy.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\dsecel.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\icfljh.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\bukfll.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\ziwtdo.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\blphxv.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\xxlhdp.dat infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINNT\ppqcns.dat infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\ieek.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\msly.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\syskj32.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\mfcnt.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\appcf32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken. File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken. File C:\WINNT\system32\ntwg32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\ezStubi.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken. File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken. File C:\WINNT\system32\winqv32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\i5n7xamyz8zl.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\2x3iwd448vshmot.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\d4yn455rgj6id.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\n22u9eav5fpox.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\aufd2doxrw3dhv.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\apobunnb8egcy.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\5kw083x4h3x.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken. File C:\WINNT\system32\pp9cx2nto686.exe infected by "Trojan-Dropper.Win32.Agent.p" Virus! Action Taken: No Action Taken.
Ok, some baddies in there to get rid of. Please first save these directions to the desktop as a text file, because you will need to copy and paste part of them later, once we are in Safe Mode.
  • Please download the Killbox.
    Unzip it to the desktop but do NOT run it yet.
  • Then please reboot into Safe Mode by restarting your computer and pressing F8 as your computer is booting up. Then select the Safe Mode option.
  • Once in Safe Mode, please run Killbox.
  • Select "Delete on Reboot".
  • Open the text with these instructions in it, and copy the names below to the clipboard by highlighting them and pressing Control-C:

    C:\WINNT\nvbjyf.dat
    C:\WINNT\ysqjly.dat
    C:\WINNT\ylvlnc.dat
    C:\WINNT\yoeztw.dat
    C:\WINNT\tncmcs.dat
    C:\WINNT\dljihs.txt
    C:\WINNT\applc32.exe
    C:\WINNT\javamk32.exe
    C:\WINNT\threaz.dat
    C:\WINNT\vwtpzx.dat
    C:\WINNT\leudgz.log
    C:\WINNT\veennk.dat
    C:\WINNT\sfgdtr.dat
    C:\WINNT\xzntvs.dat
    C:\WINNT\yrsnxw.dat
    C:\WINNT\vpyjkb.dat
    C:\WINNT\wizjfr.dat
    C:\WINNT\xbfmpu.dat
    C:\WINNT\osxepl.dat
    C:\WINNT\xkfdzq.dat
    C:\WINNT\lucvsh.dat
    C:\WINNT\wjwtgl.dat
    C:\WINNT\jldgwb.dat
    C:\WINNT\okcgzo.dat
    C:\WINNT\ofpdai.dat
    C:\WINNT\sdusmb.log
    C:\WINNT\wprppn.dat
    C:\WINNT\aapfdh.dat
    C:\WINNT\dvzodp.dat
    C:\WINNT\tylxdu.dat
    C:\WINNT\sdkmg.exe
    C:\WINNT\clabqn.dat
    C:\WINNT\vwhwka.log
    C:\WINNT\vxqqky.dat
    C:\WINNT\znkpuz.dat
    C:\WINNT\meppdk.dat
    C:\WINNT\agpred.dat
    C:\WINNT\rokanb.dat
    C:\WINNT\fkywan.dat
    C:\WINNT\gddykq.dat
    C:\WINNT\hnvnbe.dat
    C:\WINNT\cllilv.dat
    C:\WINNT\dercvy.dat
    C:\WINNT\syqdqe.dat
    C:\WINNT\iruvtp.dat
    C:\WINNT\bbapws.dat
    C:\WINNT\boioek.dat
    C:\WINNT\cqplra.dat
    C:\WINNT\hzosyo.dat
    C:\WINNT\ikumjs.dat
    C:\WINNT\cbufte.dat
    C:\WINNT\xjgjur.dat
    C:\WINNT\xcldwu.dat
    C:\WINNT\najwmi.dat
    C:\WINNT\otoqwl.dat
    C:\WINNT\swayaz.dat
    C:\WINNT\sgfakd.dat
    C:\WINNT\ntnvwa.dat
    C:\WINNT\odaphd.dat
    C:\WINNT\ydtaxl.dat
    C:\WINNT\fwfcen.dat
    C:\WINNT\gpkxgr.dat
    C:\WINNT\zogdio.dat
    C:\WINNT\eoxjfj.dat
    C:\WINNT\fycdpm.dat
    C:\WINNT\nmqijj.dat
    C:\WINNT\kdcjsr.dat
    C:\WINNT\loqdcu.dat
    C:\WINNT\nfwclm.dat
    C:\WINNT\ndvgzi.dat
    C:\WINNT\gvaacl.dat
    C:\WINNT\umjhlj.dat
    C:\WINNT\vfpbvm.dat
    C:\WINNT\qjwvhj.dat
    C:\WINNT\qccqkm.dat
    C:\WINNT\ppvvbq.dat
    C:\WINNT\qibxmt.dat
    C:\WINNT\pnaxoa.dat
    C:\WINNT\iyfzyd.dat
    C:\WINNT\lknuka.dat
    C:\WINNT\dvsond.dat
    C:\WINNT\xflsbo.dat
    C:\WINNT\gpvowx.dat
    C:\WINNT\giaiza.dat
    C:\WINNT\yqquer.dat
    C:\WINNT\sksnnl.dat
    C:\WINNT\tcypyo.dat
    C:\WINNT\ohfkkl.dat
    C:\WINNT\pzlemp.dat
    C:\WINNT\fxjxbc.dat
    C:\WINNT\xqwrmg.dat
    C:\WINNT\elxuvh.dat
    C:\WINNT\yytpce.dat
    C:\WINNT\lkisig.dat
    C:\WINNT\muousj.dat
    C:\WINNT\vsituv.dat
    C:\WINNT\hjrnsw.dat
    C:\WINNT\ibwhcz.dat
    C:\WINNT\wlnvfy.dat
    C:\WINNT\zkcfxd.dat
    C:\WINNT\auhhhg.dat
    C:\WINNT\eyjwza.dat
    C:\WINNT\zvesva.dat
    C:\WINNT\agjnyd.dat
    C:\WINNT\wklhwa.dat
    C:\WINNT\pdybye.dat
    C:\WINNT\talyve.dat
    C:\WINNT\pxynre.dat
    C:\WINNT\hidhuh.dat
    C:\WINNT\hvrnxl.dat
    C:\WINNT\aowpzo.dat
    C:\WINNT\surdrq.dat
    C:\WINNT\seextt.dat
    C:\WINNT\mtxmoh.dat
    C:\WINNT\nldoqk.dat
    C:\WINNT\yojtzv.dat
    C:\WINNT\ygowcy.dat
    C:\WINNT\dsecel.dat
    C:\WINNT\icfljh.dat
    C:\WINNT\bukfll.dat
    C:\WINNT\ziwtdo.dat
    C:\WINNT\blphxv.dat
    C:\WINNT\xxlhdp.dat
    C:\WINNT\ppqcns.dat
    C:\WINNT\system32\ieek.exe
    C:\WINNT\system32\msly.exe
    C:\WINNT\system32\syskj32.exe
    C:\WINNT\system32\mfcnt.exe
    C:\WINNT\system32\appcf32.exe
    C:\WINNT\system32\ntwg32.exe
    C:\WINNT\system32\winqv32.exe
    C:\WINNT\system32\i5n7xamyz8zl.exe
    C:\WINNT\system32\2x3iwd448vshmot.exe
    C:\WINNT\system32\d4yn455rgj6id.exe
    C:\WINNT\system32\n22u9eav5fpox.exe
    C:\WINNT\system32\aufd2doxrw3dhv.exe
    C:\WINNT\system32\apobunnb8egcy.exe
    C:\WINNT\system32\5kw083x4h3x.exe
    C:\WINNT\system32\pp9cx2nto686.exe
  • Return to Killbox, go to the menu, and choose "Paste from Clipboard".
  • Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
Reboot your computer and post a new MWAv log.

Please see my previous directions about excluding the lines with the "Invalid object" in them. They clutter the log and make it hard to read.
Sorry, thought I'd bot all the 'invalid object' entries last time but I see I missed a few. Hopefully got them all this time. Here's the new log after cleaning with Killbox: File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken. File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken. File C:\WINNT\iezm32.exe infected by "Trojan.Win32.Agent.iu" Virus! Action Taken: No Action Taken. Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "vx2 Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "weathercast Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.homesearch Browser Hijacker" found in File System! Action Taken: No Action Taken. Object "ipinsight Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "netpal Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken. File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken. File C:\WINNT\system32\ezStubi.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken. File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken.
Ok, I missed one. Can you killbox this file:
C:\WINNT\iezm32.exe


Also, can you look in the full log and find the lines that correspond to these entries and post them for me to review:
vx2 Spyware/Adware
Is this what you need? Mon Oct 03 22:18:47 2005 => Offending file found: C:\msdos.exe Mon Oct 03 22:18:47 2005 => System found infected with vx2 Spyware/Adware (msdos.exe)! Action taken: No Action Taken.
Yes, that's it. C:\msdos.exe is what we need to check out next.

Go to Jotti's malware scan at http://virusscan.jotti.org/ and upload the file for scanning, then post the log it generates for me to review.

Did you killbox that other file?
Yes, I Killboxed the other file (I'm getting pretty good at this now). I got this message when I tried to upload C:\msdos.exe for scanning: "The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file." My router comes with its own firewall (it's a router/modem/wireless hub).
Type of file: Application Description: msdos Location: C:\ Size: 0 bytes Size on disk: 0 bytes Created: 05 September 2004, 17:39:22 Modified: 05 September 2004, 17:39:24 Accessed: 03 October 2005 Attributes: Read only
Ok, you can probably delete that file. Can you also update Ad-aware with the latest definitions and run a scan with it? If you have Spybot S&D, please do the same. Let me know how the scans go and if anything cannot be removed.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI