OK, msdos.exe deleted.
Adaware scan found 0 critical objects, 17 negligible objects, deleted these and second scan was clean.
Spybot S&D found no immediate threats.
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken.
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "weathercast Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "cws.homesearch Browser Hijacker" found in File System! Action Taken: No Action Taken.
Object "ipinsight Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "netpal Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "exactsearchbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken.
File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken.
File C:\WINNT\system32\ezStubi.dll tagged as "not-a-virus:AdWare.EZula.a". Action Taken: No Action Taken.
File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken.
Ok, can I see the entries from the full log for the following:
hotbar
kazaa
weathercast
homesearch
ipinsight
netpal
exactsearchbar
istbar
smartfinder
whenu
exactsearchbar
We will remove them manually since Ad-aware and Spybot do not seem to be picking some of these up for some reason.
Here they are:
Tue Oct 04 18:49:11 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken.
Tue Oct 04 18:49:12 2005 => Offending Key found: HKLM\Software\kazaa !!!
Tue Oct 04 18:49:12 2005 => Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Tue Oct 04 18:49:12 2005 => Offending Key found: HKCU\Software\kazaa !!!
Tue Oct 04 18:49:12 2005 => Object "kazaa Spyware/Adware" found in File System! Action Taken: No Action Taken.
Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\weather.exe
Tue Oct 04 18:49:14 2005 => System found infected with weathercast Spyware/Adware (weather.exe)! Action taken: No Action Taken.
Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\appsj.exe
Tue Oct 04 18:49:14 2005 => System found infected with cws.homesearch Browser Hijacker (appsj.exe)! Action taken: No Action Taken.
Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\Inf\ipinsigt.pnf
Tue Oct 04 18:49:14 2005 => System found infected with ipinsight Spyware/Adware (ipinsigt.pnf)! Action taken: No Action Taken.
Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\system32\netpals.dll
Tue Oct 04 18:49:14 2005 => System found infected with netpal Spyware/Adware (netpals.dll)! Action taken: No Action Taken.
Tue Oct 04 18:49:14 2005 => Offending file found: C:\WINNT\system32\ezstubi.dll
Tue Oct 04 18:49:14 2005 => System found infected with exactsearchbar Spyware/Adware (ezstubi.dll)! Action taken: No Action Taken.
Tue Oct 04 18:49:17 2005 => Offending Folder found: C:\Documents and Settings\leo.quigley\Application Data\lycos\sidesearch
Tue Oct 04 18:49:17 2005 => Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Tue Oct 04 18:49:17 2005 => Offending Folder found: C:\Documents and Settings\leo.quigley\Favorites\sites about
Tue Oct 04 18:49:17 2005 => Object "smartfinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\search the web.url
Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (search the web.url)! Action taken: No Action Taken.
Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\only sex website.url
Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (only sex website.url)! Action taken: No Action Taken.
Tue Oct 04 18:49:17 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Favorites\seven days of free porn.url
Tue Oct 04 18:49:17 2005 => System found infected with smartfinder Spyware/Adware (seven days of free porn.url)! Action taken: No Action Taken.
Tue Oct 04 18:49:19 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html
Tue Oct 04 18:49:19 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken.
Tue Oct 04 18:49:20 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\Temporary Internet Files\search.html
Tue Oct 04 18:49:20 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken.
Tue Oct 04 18:49:23 2005 => Offending file found: C:\WINNT\system32\ezstubi.dll
Tue Oct 04 18:49:23 2005 => System found infected with exactsearchbar Spyware/Adware (C:\WINNT\system32\ezstubi.dll)! Action taken: No Action Taken.
Please run Notepad and paste the following text into a new file:
REGEDIT4
[-HKEY_LOCAL_MACHINE\Software\kazaa]
[-HKEY_CURRENT_USER\Software\kazaa]
Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.
Next, please enable viewing of hidden files as follows:
Go to My Computer, and click on the "Tools" menu
Click "Folder options"
Select the "View" tab
Make sure "Show hidden files and folders" is selected
Make sure "Hide extensions for known file types" is unchecked
Make sure "Hide protected operating system files (recommended)" is unchecked
Delete the following files and folders (if found):
C:\WINNT\weather.exe <–This file
C:\WINNT\appsj.exe <–This file
C:\WINNT\Inf\ipinsigt.pnf <–This file
C:\WINNT\system32\netpals.dll <–This file
C:\WINNT\system32\ezstubi.dll <–This file
C:\Documents and Settings\leo.quigley\Application Data\lycos\sidesearch <–This folder and its contents
C:\Documents and Settings\leo.quigley\Favorites\sites about <–This folder and its contents
C:\Documents and Settings\leo.quigley\Favorites\search the web.url <–This file
C:\Documents and Settings\leo.quigley\Favorites\only sex website.url <–This file
C:\Documents and Settings\leo.quigley\Favorites\seven days of free porn.url <–This file
C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html <–This file
Found them all except the last one. No sign of it in the location given.
Here's the log from the bottom window:
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken.
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "whenu.sidefinder Spyware/Adware" found in File System! Action Taken: No Action Taken.
File C:\WINNT\system32\NLNP13.dll tagged as "not-a-virus:AdWare.IGetNet". Action Taken: No Action Taken.
File C:\WINNT\system32\ctbv2.dll tagged as "not-a-virus:AdWare.Sahat.g". Action Taken: No Action Taken.
File C:\WINNT\system32\CometTB.dll tagged as "not-a-virus:AdWare.Win32.Comet.ad". Action Taken: No Action Taken.
And here are the relevant lines from the full log:
Tue Oct 04 22:58:36 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken.
Tue Oct 04 22:58:45 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\temporary internet files\search.html
Tue Oct 04 22:58:45 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken.
Tue Oct 04 22:58:46 2005 => Offending file found: C:\Documents and Settings\leo.quigley\Local Settings\Temporary Internet Files\search.html
Tue Oct 04 22:58:46 2005 => System found infected with whenu.sidefinder Spyware/Adware (search.html)! Action taken: No Action Taken.
Download: CCleaner (freeware) http://www.majorgeeks.com/download4191.html
Once installed, run CCleaner click the Windows
Select the following: [external image: Posted Image]
Next: click Options click the Settings tab
Uncheck: "Only delete files older than 48 hrs.", click Ok
Then click Run Cleaner (bottom right) then Exit.
Delete the last 3 files found in the log, then run a new MWav scan and post the log. Almost there.
Cleaner didn't have a checkbox for Old Prefetch Data. Otherwise, done as requested and here is the new log:
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
File C:\PROGRA~1\ORL\VNC\OMNITH~1.DLL tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.g. No Action Taken.
File C:\PROGRA~1\ORL\VNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.333. No Action Taken.
Object "hotbar Spyware/Adware" found in File System! Action Taken: No Action Taken.
Wed Oct 05 08:41:38 2005 => System found infected with hotbar Spyware/Adware ({b195b3b3-8a05-11d3-97a4-0004aca6948e})! Action taken: No Action Taken.
Please download the Registry Search tool by clicking on the "hard drive" icon three quarters of the way down this page. Save it to the desktop and run it. If you get an alert from your antivirus about scripting, choose to allow the script to run. Search for b195b3b3-8a05-11d3-97a4-0004aca6948e and click OK. Post the logfile from the tool here for me.