This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan-Generic2.JGV

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
My AVG Resident Shield is telling me that while it was trying to open C:\Windows\System32\pptp32.dll a Trojan Horse Back Door Generic2.JGV is present.

I have done all the scans ie AVG,Stinger, Housecall,Disk Clean-up,CWShredder,ad-aware,Spybot, in both normal and safe mode with System Restore off, all said I had no problem, but the message was coming up every 10 seconds !!
Spybot found an error, message was - Zwax(ungutiger Datentyp fur")
AVG had reading error in Boot Sector of disk C and Partition table (MBR)

I tried to delete all my temporary Internet files and all Temp files tho found two in the Temp file that would not let me delete them one was file 01083070 the second was AAWTMP, I don't know if this is significant.

Have HijackThis Log and would appreciate any help, thank you



Logfile of HijackThis v1.99.1
Scan saved at 12:05:29 PM, on 25/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Barbara\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122263461303
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: pptp32 - C:\WINDOWS\SYSTEM32\pptp32.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
Hope there is something here that says what my problem is

Regards
Barb
Hello Barb33, welcome to the TC Forum.


Download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES.
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
The ewido security suite is now known as ewido anti-malware. If additional information is needed, click A Quick Guide.
  • Please download and install ewido anti-malware v3.5. If ewido finds something that you KNOW is legitimate (watch for alerts that have the word "Heuristic" in them - these may actually be false positives) select "none" as the action. DO NOT check "Perform action with all infections." If you are unsure of an entry, select "none" for the time being.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido by double-clicking the "e" icon on your desktop.
  • The program will now go to the main screen.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click "Update".
    • Then click on "Start Update".
    • The update will begin and a progress bar will show the updates being installed. If you are having problems with the updater, click Update ewido.
    • After the update finishes, the status bar at the bottom will display "Update successful".
  • After the updates are installed, click on Scanner and select "Settings".
    • Under the bottom section "What to Scan?" select "Scan every file".
    • Select "OK" and you will return to scanning options.
  • Click on "Complete System Scan". This can take a while to complete so please be patient.
  • While the scan is in progress, you will be prompted to clean the first infected file it finds. Choose "clean", then CHECK or UNCHECK "Perform action on all infections" and click "OK". Note: You will have to watch the scan all the way through and delete items manually.
  • After the scan has completed, ewido will create a report.
  • There will be a button located on the bottom of the screen named "Save report". Click "Save report" [to your desktop].
  • Exit ewido anti-malware when done.
  • Note: ewido is a free trial product for 14 days. Since ewido is a trial version, the realtime guard and automatic update will stop functioning after 14 days (which is the reason we uncheck them during installation). You can use ewido as an on-demand scanner (recommended) but you will have to manually update the definition file each time you scan by clicking on “Update” and “Start Update”.
Please post the contents of C:\vundofix.txt, the ewido anti-malware log and a new HijackThis log.
Hi LDTate

Thank you for your reply, I have done the Vundo Fix already, I looked thru all the other posts and found a couple that sounded the same as mine to try to help myself a little - I am a novice at this …but learning fast !! the scan came up with nothing to fix, I downloaded the Ewido Security Suite trial version….also recommended from another posting, ran in Safe Mode, found something in there ….
Here is the report:-
——————————————————–
ewido anti-malware - Scan report
———————————————————

+ Created on: 6:22:20 PM, 27/02/2006
+ Report-Checksum: 21CA52E

+ Scan result:

No infected objects found.


::Report End

Sorry ….. this is a second scan that I did just now, didn't realise it would delete the first one.
That one had 10 infected files, two were Trojans - Haxdoor….sorry I feel so silly now…I should have just waited for the reply but just wanted to get rid of the message coming thru from AVG Resident Shield!!

I also did something else that is probably not good either.
I read on the posting that 020
(which in my case was Winlogin Notify: pptp32 - C:\WINDOWS\SYSTEM32\pptp32.dll)
could be deleted ……so I did….hope this hasn't mucked it all up.

My HiJackThis Log is here……………….

Logfile of HijackThis v1.99.1
Scan saved at 2:57:35 AM, on 27/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Barbara\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122263461303
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37610.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe

Thank you for your time with this problem..
I am still getting the Resident shield popping up with the warning: that while it was trying to open C:\Windows\System32\pptp32.dll a Trojan Horse Back Door Generic2.JGV is present.

Could you tell what the Spybot message Zwas..etc is saying???

I hope I have done all that you have asked, Thank you so much, I know you are very busy helping everyone. I won't do any more now till I hear from you …….I promise !!!!

Regards
Barb
The "Z-Demon/Zwax" error is a little bug.
http://forums.spybot.info/showthread.php?t=2191


Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.

Exit Spy Sweeper.

Empty Recycle Bin

Reboot and "copy/paste" a new HJT log as well as the Resullts from Spy Sweeper file into this thread.
Also please describe how your computer behaves at the moment.
Hi LDTate
Thank you for your patience, I have downloaded and used the Spy Sweeper, but as usual nothing is ever easy for me……I followed your directions up to Remove…Select All …….Next…..
The computer then came up with a message saying that some files in Windows had been replaced by unrecognized versions, could I please insert DirectX9.0 Installation Disk now…….

Well, I didn't know what this was so rang my brother, I found a copy on a PC magazine disc and inserted that but it kept saying that it was the wrong disc, I opened windows Explorer, found the DirectX on the CD and clicked on the setup button, it only took a couple of seconds and all was done, closed Explorer, went back to the window asking for the DirectX Installation Disk, didn't touch anything else …..but my computer re-started itself.

I went back into Sweeper, ran another scan, it didn't ask for the DirectX this time just ran thru, so did what was asked to the end, went to results and copied the results of both tests….the second scan is reported first tho……


********
1:44 PM: | Start of Session, Tuesday, 28 February 2006 |
1:44 PM: Spy Sweeper started
1:44 PM: Sweep initiated using definitions version 622
1:44 PM: Starting Memory Sweep
1:51 PM: Memory Sweep Complete, Elapsed Time: 00:06:46
1:51 PM: Starting Registry Sweep
1:53 PM: Registry Sweep Complete, Elapsed Time:00:02:07
1:53 PM: Starting Cookie Sweep
1:53 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
1:53 PM: Starting File Sweep
2:16 PM: Found System Monitor: potentially rootkit-masked files
2:16 PM: ____swmxs (ID = 0)
2:16 PM: rdn.class (ID = 0)
2:16 PM: gtb5.tmp.cab (ID = 0)
2:16 PM: h2r3b.tmp (ID = 0)
2:16 PM: qmark.class (ID = 0)
2:16 PM: quit.bmp (ID = 0)
2:16 PM: qtinstallerhelper.dll (ID = 0)
2:16 PM: rdn.class (ID = 0)
2:16 PM: quit.gif (ID = 0)
2:16 PM: ____swmxs (ID = 0)
2:16 PM: rd3e.tmp (ID = 0)
2:16 PM: rdn.class (ID = 0)
2:16 PM: qmgr.inf (ID = 0)
2:16 PM: quit.gif (ID = 0)
2:16 PM: quit.bmp (ID = 0)
2:16 PM: ____swmx (ID = 0)
2:16 PM: ____swmxs (ID = 0)
2:16 PM: dsc.swf (ID = 0)
2:16 PM: h2re1.tmp (ID = 0)
2:16 PM: ____swmx (ID = 0)
2:16 PM: qmark.class (ID = 0)
2:16 PM: rd2.tmp (ID = 0)
2:16 PM: hijackthis.log (ID = 0)
2:16 PM: appcompat.txt (ID = 0)
2:16 PM: logo_cable.bmp (ID = 0)
2:16 PM: qmgr.cab (ID = 0)
2:16 PM: ____swmx (ID = 0)
2:17 PM: ____mmfp.ocx (ID = 0)
2:17 PM: rd3.tmp (ID = 0)
2:17 PM: ____mmfp.ocx (ID = 0)
2:17 PM: ____mmfp.ocx (ID = 0)
2:17 PM: jusched.log (ID = 0)
2:17 PM: gtb5.tmp (ID = 0)
2:17 PM: msiee48f.log (ID = 0)
2:17 PM: msiaf157.log (ID = 0)
2:17 PM: backup-20060226-223906-453 (ID = 0)
2:17 PM: msidde6c.log (ID = 0)
2:17 PM: java_install_reg.log (ID = 0)
2:17 PM: wer3b2.tmp (ID = 0)
2:17 PM: dsc_full.msk (ID = 0)
2:17 PM: pannel_full.msk (ID = 0)
2:17 PM: pannel.msk (ID = 0)
2:17 PM: none.msk (ID = 0)
2:17 PM: dsc.msk (ID = 0)
2:17 PM: msi3656a.log (ID = 0)
2:17 PM: ____ldr (ID = 0)
2:17 PM: ____ldr (ID = 0)
2:17 PM: ____ldr (ID = 0)
2:17 PM: File Sweep Complete, Elapsed Time: 00:23:44
2:17 PM: Full Sweep has completed. Elapsed time 00:30:22
2:17 PM: Traces Found: 48
2:17 PM: Removal process initiated
2:18 PM: Quarantining All Traces: potentially rootkit-masked files
2:19 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
2:19 PM: ____swmxs is in use. It will be removed on reboot.
2:19 PM: rdn.class is in use. It will be removed on reboot.
2:19 PM: gtb5.tmp.cab is in use. It will be removed on reboot.
2:19 PM: h2r3b.tmp is in use. It will be removed on reboot.
2:19 PM: qmark.class is in use. It will be removed on reboot.
2:19 PM: quit.bmp is in use. It will be removed on reboot.
2:19 PM: qtinstallerhelper.dll is in use. It will be removed on reboot.
2:19 PM: rdn.class is in use. It will be removed on reboot.
2:19 PM: quit.gif is in use. It will be removed on reboot.
2:19 PM: ____swmxs is in use. It will be removed on reboot.
2:19 PM: rd3e.tmp is in use. It will be removed on reboot.
2:19 PM: rdn.class is in use. It will be removed on reboot.
2:19 PM: qmgr.inf is in use. It will be removed on reboot.
2:19 PM: quit.gif is in use. It will be removed on reboot.
2:19 PM: quit.bmp is in use. It will be removed on reboot.
2:19 PM: ____swmx is in use. It will be removed on reboot.
2:19 PM: ____swmxs is in use. It will be removed on reboot.
2:19 PM: dsc.swf is in use. It will be removed on reboot.
2:19 PM: h2re1.tmp is in use. It will be removed on reboot.
2:19 PM: ____swmx is in use. It will be removed on reboot.
2:19 PM: qmark.class is in use. It will be removed on reboot.
2:19 PM: rd2.tmp is in use. It will be removed on reboot.
2:19 PM: hijackthis.log is in use. It will be removed on reboot.
2:19 PM: appcompat.txt is in use. It will be removed on reboot.
2:19 PM: logo_cable.bmp is in use. It will be removed on reboot.
2:19 PM: qmgr.cab is in use. It will be removed on reboot.
2:19 PM: ____swmx is in use. It will be removed on reboot.
2:19 PM: ____mmfp.ocx is in use. It will be removed on reboot.
2:19 PM: rd3.tmp is in use. It will be removed on reboot.
2:19 PM: ____mmfp.ocx is in use. It will be removed on reboot.
2:19 PM: ____mmfp.ocx is in use. It will be removed on reboot.
2:19 PM: jusched.log is in use. It will be removed on reboot.
2:19 PM: gtb5.tmp is in use. It will be removed on reboot.
2:19 PM: msiee48f.log is in use. It will be removed on reboot.
2:19 PM: msiaf157.log is in use. It will be removed on reboot.
2:19 PM: backup-20060226-223906-453 is in use. It will be removed on reboot.
2:19 PM: msidde6c.log is in use. It will be removed on reboot.
2:19 PM: java_install_reg.log is in use. It will be removed on reboot.
2:19 PM: wer3b2.tmp is in use. It will be removed on reboot.
2:19 PM: dsc_full.msk is in use. It will be removed on reboot.
2:19 PM: pannel_full.msk is in use. It will be removed on reboot.
2:19 PM: pannel.msk is in use. It will be removed on reboot.
2:19 PM: none.msk is in use. It will be removed on reboot.
2:19 PM: dsc.msk is in use. It will be removed on reboot.
2:19 PM: msi3656a.log is in use. It will be removed on reboot.
2:19 PM: ____ldr is in use. It will be removed on reboot.
2:19 PM: ____ldr is in use. It will be removed on reboot.
2:19 PM: ____ldr is in use. It will be removed on reboot.
2:19 PM: Preparing to restart your computer. Please wait…
2:19 PM: Removal process completed. Elapsed time 00:01:53
********
12:33 PM: | Start of Session, Tuesday, 28 February 2006 |
12:33 PM: Spy Sweeper started
12:33 PM: Sweep initiated using definitions version 622
12:34 PM: Starting Memory Sweep
12:39 PM: Memory Sweep Complete, Elapsed Time: 00:05:46
12:39 PM: Starting Registry Sweep
12:41 PM: Registry Sweep Complete, Elapsed Time:00:01:53
12:41 PM: Starting Cookie Sweep
12:41 PM: Found Spy Cookie: military cookie
12:41 PM: debi@military[1].txt (ID = 2996)
12:41 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
12:41 PM: Starting File Sweep
12:49 PM: Found Trojan Horse: trojan-backdoor-haxdoor
12:49 PM: qz.dll (ID = 262)
1:00 PM: pptp64.sys (ID = 261)
1:01 PM: pptp32.dll (ID = 262)
1:01 PM: Found Adware: nvdialer
1:01 PM: games.exe (ID = 137596)
1:03 PM: ps.a3d (ID = 233118)
1:03 PM: Found System Monitor: potentially rootkit-masked files
1:03 PM: qlnh7hnx.dat (ID = 0)
1:03 PM: quit.bmp (ID = 0)
1:03 PM: quit.gif (ID = 0)
1:03 PM: qtfont.for (ID = 0)
1:03 PM: qlnh7hnx.zip (ID = 0)
1:03 PM: quicktimeplayerextras.qpx (ID = 0)
1:03 PM: quattro.wb2 (ID = 0)
1:03 PM: quake.smk (ID = 0)
1:03 PM: quicktimefavorites.qtr (ID = 0)
1:03 PM: qlnh7hnx.zip (ID = 0)
1:03 PM: qlnh7hnx.dat (ID = 0)
1:03 PM: recovr32.cnv (ID = 0)
1:03 PM: quicktime read me.lnk (ID = 0)
1:03 PM: quicktime player.lnk (ID = 0)
1:03 PM: rdpclip.exe (ID = 0)
1:03 PM: ____swmxs (ID = 0)
1:03 PM: quicktime.qtp (ID = 0)
1:03 PM: rdpwd.sys (ID = 0)
1:03 PM: rdpdr.sys (ID = 0)
1:03 PM: rdbss.sys (ID = 0)
1:03 PM: qtfont.qfn (ID = 0)
1:03 PM: quattro.wb2 (ID = 0)
1:03 PM: qtplugin.log (ID = 0)
1:03 PM: quickentype.gif (ID = 0)
1:03 PM: rdesktop.chm (ID = 0)
1:03 PM: rdocurs.dll (ID = 0)
1:03 PM: quit.bmp (ID = 0)
1:03 PM: rdn.class (ID = 0)
1:03 PM: recl.ico (ID = 0)
1:03 PM: recs.ico (ID = 0)
1:03 PM: rdsaddin.exe (ID = 0)
1:03 PM: qasf.dll (ID = 0)
1:03 PM: rec.cfg (ID = 0)
1:03 PM: quattro.wb2 (ID = 0)
1:03 PM: quicktimestreamingextras.qtx (ID = 0)
1:03 PM: rdshost.exe (ID = 0)
1:03 PM: rdsaddin.exe (ID = 0)
1:03 PM: rdpwsx.dll (ID = 0)
1:03 PM: rdpsnd.dll (ID = 0)
1:03 PM: rdpdd.dll (ID = 0)
1:03 PM: rdpclip.exe (ID = 0)
1:03 PM: rdchost.dll (ID = 0)
1:03 PM: query.dll (ID = 0)
1:03 PM: quartz.dll (ID = 0)
1:03 PM: qmgrprxy.dll (ID = 0)
1:03 PM: qmgr.dll (ID = 0)
1:03 PM: qedit.dll (ID = 0)
1:03 PM: qdvd.dll (ID = 0)
1:03 PM: qcap.dll (ID = 0)
1:03 PM: quit.gif (ID = 0)
1:03 PM: quicktimeplugin.class (ID = 0)
1:03 PM: recf3260.dll (ID = 0)
1:03 PM: quicktimevrauthoring.qtx (ID = 0)
1:03 PM: quicktimecapture.qtx (ID = 0)
1:03 PM: quicktimestreamingauthoring.qtx (ID = 0)
1:03 PM: rdpsnd.dll (ID = 0)
1:03 PM: gtb5.tmp.cab (ID = 0)
1:03 PM: quicktime read me.htm (ID = 0)
1:03 PM: quicktimecheck.ocx (ID = 0)
1:03 PM: qwrdrt32.hlp (ID = 0)
1:03 PM: quit.bmp (ID = 0)
1:03 PM: quit.gif (ID = 0)
1:03 PM: qmark.class (ID = 0)
1:03 PM: quick.ime (ID = 0)
1:03 PM: quick.ime (ID = 0)
1:03 PM: h2r3b.tmp (ID = 0)
1:03 PM: quarantinedresourceimpl.class (ID = 0)
1:03 PM: quicktimevr.qtx (ID = 0)
1:03 PM: qmark.class (ID = 0)
1:03 PM: qsg_ds_1.exe (ID = 0)
1:03 PM: qmark.gif (ID = 0)
1:03 PM: quicktimeplugin.class (ID = 0)
1:03 PM: question_icon.jpg (ID = 0)
1:03 PM: qmgr0.dat (ID = 0)
1:03 PM: quicktimewebhelper.qtx (ID = 0)
1:03 PM: quake_rumble.wav (ID = 0)
1:03 PM: quake_explode.wav (ID = 0)
1:03 PM: qmark.class (ID = 0)
1:03 PM: quit.bmp (ID = 0)
1:03 PM: qtinstallerhelper.dll (ID = 0)
1:03 PM: rdn.class (ID = 0)
1:03 PM: quit.gif (ID = 0)
1:03 PM: rdn.class (ID = 0)
1:03 PM: quarantinedresourceimpl.class (ID = 0)
1:03 PM: quicktimempeg4.qtx (ID = 0)
1:03 PM: recover.exe (ID = 0)
1:03 PM: rdpcfgex.dll (ID = 0)
1:03 PM: rdpcdd.sys (ID = 0)
1:04 PM: qmark.class (ID = 0)
1:04 PM: qwinsta.exe (ID = 0)
1:04 PM: quser.exe (ID = 0)
1:04 PM: query.exe (ID = 0)
1:04 PM: qosname.dll (ID = 0)
1:04 PM: qappsrv.exe (ID = 0)
1:04 PM: qmspub.hlp (ID = 0)
1:04 PM: quicktimempeg.qtx (ID = 0)
1:04 PM: recreation.png (ID = 0)
1:04 PM: rdrmsgenu.pdf (ID = 0)
1:04 PM: rdpcfgex.dll (ID = 0)
1:04 PM: ____swmxs (ID = 0)
1:04 PM: rdisk.dll (ID = 0)
1:04 PM: rd3e.tmp (ID = 0)
1:04 PM: rdpwsx.dll (ID = 0)
1:04 PM: quote.tz3 (ID = 0)
1:04 PM: rdpwd.sys (ID = 0)
1:04 PM: rdn.class (ID = 0)
1:04 PM: q2mny.dll (ID = 0)
1:04 PM: qmgr.pnf (ID = 0)
1:04 PM: quicktimemusic.qtx (ID = 0)
1:04 PM: qmgr.dll (ID = 0)
1:04 PM: quinto.hlp (ID = 0)
1:04 PM: quicktimeimage.qtx (ID = 0)
1:04 PM: qs98.dll (ID = 0)
1:04 PM: quicktimestreaming.qtx (ID = 0)
1:04 PM: quicktimempeg4authoring.qtx (ID = 0)
1:04 PM: redhat.jpg (ID = 0)
1:04 PM: quattro.wb2 (ID = 0)
1:04 PM: quicktimeupdatehelper.exe (ID = 0)
1:04 PM: quarantine.dll.update (ID = 0)
1:04 PM: qg_banner.gif (ID = 0)
1:04 PM: rdsf3260.dll (ID = 0)
1:04 PM: qmgr.inf (ID = 0)
1:04 PM: quicktimeessentials.qtx (ID = 0)
1:04 PM: quit.gif (ID = 0)
1:04 PM: quit.bmp (ID = 0)
1:04 PM: quicktimeeffects.qtx (ID = 0)
1:04 PM: quickguide.css (ID = 0)
1:04 PM: recover.exe (ID = 0)
1:04 PM: qmgr.inf (ID = 0)
1:04 PM: qosname.dll (ID = 0)
1:04 PM: qosconcepts.chm (ID = 0)
1:04 PM: ____swmx (ID = 0)
1:04 PM: recycle.wav (ID = 0)
1:04 PM: qif.dll (ID = 0)
1:04 PM: qyzylorda (ID = 0)
1:04 PM: recycle.chm (ID = 0)
1:04 PM: rectngle.jpg (ID = 0)
1:04 PM: qread.dll (ID = 0)
1:04 PM: rdrmsgsplash.pdf (ID = 0)
1:04 PM: ____swmxs (ID = 0)
1:04 PM: quicktimeinternetextras.qtx (ID = 0)
1:04 PM: recipe, full page.wps (ID = 0)
1:04 PM: qrcode.pmp (ID = 0)
1:04 PM: h2re1.tmp (ID = 0)
1:04 PM: rdtone.htm (ID = 0)
1:04 PM: ____swmx (ID = 0)
1:04 PM: qmark.class (ID = 0)
1:04 PM: recall.dll (ID = 0)
1:04 PM: quikanim.ppt (ID = 0)
1:04 PM: recommending a strategy.pot (ID = 0)
1:04 PM: rdchost.dll (ID = 0)
1:04 PM: rdn.class (ID = 0)
1:04 PM: quadrant.pot (ID = 0)
1:04 PM: qtplugininstaller.exe (ID = 0)
1:04 PM: qryint32.dll (ID = 0)
1:04 PM: quad.elm (ID = 0)
1:04 PM: quicktime3gpp.qtx (ID = 0)
1:04 PM: recipe cards, 4x6.wdb (ID = 0)
1:04 PM: rdpdd.dll (ID = 0)
1:04 PM: quicklaunch.lnk (ID = 0)
1:04 PM: recital flyer.wps (ID = 0)
1:04 PM: qartglry.hlp (ID = 0)
1:04 PM: recycle.wmf (ID = 0)
1:04 PM: quicktimemusicalinstruments.qtx (ID = 0)
1:04 PM: qappsrv.exe (ID = 0)
1:04 PM: rd2.tmp (ID = 0)
1:04 PM: qwinsta.exe (ID = 0)
1:04 PM: quicktimeauthoring.qtx (ID = 0)
1:04 PM: recogn.bct (ID = 0)
1:04 PM: hijackthis.log (ID = 0)
1:04 PM: logo_cable.bmp (ID = 0)
1:04 PM: qdu.exe-27ba8389.pf (ID = 0)
1:04 PM: qmark.acs (ID = 0)
1:04 PM: quarry.wav (ID = 0)
1:04 PM: qrtf98.dll (ID = 0)
1:04 PM: qprocess.exe (ID = 0)
1:04 PM: qmgr.cab (ID = 0)
1:04 PM: ____swmx (ID = 0)
1:04 PM: quinto.exe (ID = 0)
1:04 PM: qtuninst.dll (ID = 0)
1:04 PM: qasf.dll (ID = 0)
1:04 PM: dsc.swf (ID = 0)
1:04 PM: qtinfo.exe (ID = 0)
1:04 PM: qasf.dll (ID = 0)
1:04 PM: quicktime.cpl (ID = 0)
1:04 PM: quarantine.dll (ID = 0)
1:04 PM: questionaire.dbx (ID = 0)
1:04 PM: recogn24.bct (ID = 0)
1:04 PM: qasf.dll (ID = 0)
1:04 PM: recording.ocx (ID = 0)
1:04 PM: query.dll (ID = 0)
1:04 PM: ____mmfp.ocx (ID = 0)
1:04 PM: qcap.dll (ID = 0)
1:04 PM: rdr70.itw (ID = 0)
1:04 PM: quicktime.mpp (ID = 0)
1:04 PM: qdv.dll (ID = 0)
1:04 PM: rd3.tmp (ID = 0)
1:04 PM: qasf.dll (ID = 0)
1:04 PM: ____mmfp.ocx (ID = 0)
1:04 PM: quicksilver.wmz (ID = 0)
1:04 PM: ____mmfp.ocx (ID = 0)
1:04 PM: qttask.exe-342507fb.pf (ID = 0)
1:04 PM: qedwipes.dll (ID = 0)
1:04 PM: qcap.dll (ID = 0)
1:04 PM: qcap.dll (ID = 0)
1:04 PM: qdvd.dll (ID = 0)
1:04 PM: recipesbtf.pdf (ID = 0)
1:04 PM: qdvd.dll (ID = 0)
1:04 PM: qdv.dll (ID = 0)
1:04 PM: qedwipes.dll (ID = 0)
1:04 PM: quicktimeplayer.exe (ID = 0)
1:04 PM: qedit.dll (ID = 0)
1:04 PM: qedit.dll (ID = 0)
1:04 PM: qt-mt335.dll (ID = 0)
1:04 PM: quartz.dll (ID = 0)
1:04 PM: rdbss.sys (ID = 0)
1:04 PM: rdpdr.sys (ID = 0)
1:04 PM: rdpcdd.sys (ID = 0)
1:04 PM: jusched.log (ID = 0)
1:04 PM: qttask.exe (ID = 0)
1:04 PM: quicktime.qts (ID = 0)
1:04 PM: qtplugin.ocx (ID = 0)
1:04 PM: qmgrprxy.dll (ID = 0)
1:04 PM: qmgr1.dat (ID = 0)
1:04 PM: quartz.dll (ID = 0)
1:04 PM: quicktimeupdater.exe (ID = 0)
1:04 PM: quarantinedresource.class (ID = 0)
1:04 PM: quarantinedresourceexception.class (ID = 0)
1:04 PM: quarantinedresource.class (ID = 0)
1:04 PM: quarantinedresourceexception.class (ID = 0)
1:04 PM: gtb5.tmp (ID = 0)
1:04 PM: msiee48f.log (ID = 0)
1:04 PM: msiaf157.log (ID = 0)
1:04 PM: backup-20060226-223906-453 (ID = 0)
1:04 PM: msidde6c.log (ID = 0)
1:04 PM: java_install_reg.log (ID = 0)
1:04 PM: dsc_full.msk (ID = 0)
1:04 PM: pannel_full.msk (ID = 0)
1:04 PM: pannel.msk (ID = 0)
1:04 PM: none.msk (ID = 0)
1:04 PM: dsc.msk (ID = 0)
1:04 PM: q312370.log (ID = 0)
1:04 PM: quad.inf (ID = 0)
1:04 PM: quinto.cnt (ID = 0)
1:04 PM: quote.htm (ID = 0)
1:04 PM: quote.gif (ID = 0)
1:04 PM: qmspub.gid (ID = 0)
1:04 PM: qwrdrt32.fts (ID = 0)
1:04 PM: qartglry.fts (ID = 0)
1:04 PM: qantas airways.url (ID = 0)
1:04 PM: quicktime updater.lnk (ID = 0)
1:04 PM: qartglry.gid (ID = 0)
1:04 PM: qwrdrt32.gid (ID = 0)
1:04 PM: ____ldr (ID = 0)
1:04 PM: ____ldr (ID = 0)
1:04 PM: ____ldr (ID = 0)
1:04 PM: qsy.bmp (ID = 0)
1:04 PM: qsyma.bmp (ID = 0)
1:04 PM: qsim.bmp (ID = 0)
1:04 PM: qsbm.bmp (ID = 0)
1:05 PM: qantas airways.url (ID = 0)
1:05 PM: rectangle.gif (ID = 0)
1:05 PM: recife (ID = 0)
1:05 PM: qatar (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: question.gif (ID = 0)
1:05 PM: stt82.ini (ID = 0)
1:05 PM: klgcptini.dat (ID = 0)
1:05 PM: queenandscotssoldiers.jpg (ID = 0)
1:05 PM: question.pps (ID = 0)
1:05 PM: recorder group.jpg (ID = 0)
1:05 PM: quaestor.sav (ID = 0)
1:05 PM: qantas airways.url (ID = 0)
1:05 PM: Warning: File not found
1:05 PM: Warning: File not found
1:07 PM: quicktime read me.lnk (ID = 0)
1:07 PM: quicktime player.lnk (ID = 0)
1:07 PM: 40 games.lnk (ID = 137596)
1:07 PM: File Sweep Complete, Elapsed Time: 00:26:06
1:07 PM: Full Sweep has completed. Elapsed time 00:33:55
1:07 PM: Traces Found: 287
1:10 PM: Removal process initiated
1:10 PM: Quarantining All Traces: potentially rootkit-masked files
1:21 PM: potentially rootkit-masked files is in use. It will be removed on reboot.
1:21 PM: ____swmxs is in use. It will be removed on reboot.
1:21 PM: rdn.class is in use. It will be removed on reboot.
1:21 PM: gtb5.tmp.cab is in use. It will be removed on reboot.
1:21 PM: h2r3b.tmp is in use. It will be removed on reboot.
1:21 PM: qmark.class is in use. It will be removed on reboot.
1:21 PM: quit.bmp is in use. It will be removed on reboot.
1:21 PM: qtinstallerhelper.dll is in use. It will be removed on reboot.
1:21 PM: rdn.class is in use. It will be removed on reboot.
1:21 PM: quit.gif is in use. It will be removed on reboot.
1:21 PM: ____swmxs is in use. It will be removed on reboot.
1:21 PM: rd3e.tmp is in use. It will be removed on reboot.
1:21 PM: rdn.class is in use. It will be removed on reboot.
1:21 PM: qmgr.inf is in use. It will be removed on reboot.
1:21 PM: quit.gif is in use. It will be removed on reboot.
1:21 PM: quit.bmp is in use. It will be removed on reboot.
1:21 PM: ____swmx is in use. It will be removed on reboot.
1:21 PM: ____swmxs is in use. It will be removed on reboot.
1:21 PM: h2re1.tmp is in use. It will be removed on reboot.
1:21 PM: ____swmx is in use. It will be removed on reboot.
1:21 PM: qmark.class is in use. It will be removed on reboot.
1:21 PM: rd2.tmp is in use. It will be removed on reboot.
1:21 PM: hijackthis.log is in use. It will be removed on reboot.
1:21 PM: logo_cable.bmp is in use. It will be removed on reboot.
1:21 PM: qmgr.cab is in use. It will be removed on reboot.
1:21 PM: ____swmx is in use. It will be removed on reboot.
1:21 PM: dsc.swf is in use. It will be removed on reboot.
1:21 PM: ____mmfp.ocx is in use. It will be removed on reboot.
1:21 PM: rd3.tmp is in use. It will be removed on reboot.
1:21 PM: ____mmfp.ocx is in use. It will be removed on reboot.
1:21 PM: ____mmfp.ocx is in use. It will be removed on reboot.
1:21 PM: jusched.log is in use. It will be removed on reboot.
1:21 PM: qttask.exe is in use. It will be removed on reboot.
1:21 PM: gtb5.tmp is in use. It will be removed on reboot.
1:21 PM: msiee48f.log is in use. It will be removed on reboot.
1:21 PM: msiaf157.log is in use. It will be removed on reboot.
1:21 PM: backup-20060226-223906-453 is in use. It will be removed on reboot.
1:21 PM: msidde6c.log is in use. It will be removed on reboot.
1:21 PM: java_install_reg.log is in use. It will be removed on reboot.
1:21 PM: dsc_full.msk is in use. It will be removed on reboot.
1:21 PM: pannel_full.msk is in use. It will be removed on reboot.
1:21 PM: pannel.msk is in use. It will be removed on reboot.
1:21 PM: none.msk is in use. It will be removed on reboot.
1:21 PM: dsc.msk is in use. It will be removed on reboot.
1:21 PM: ____ldr is in use. It will be removed on reboot.
1:21 PM: ____ldr is in use. It will be removed on reboot.
1:21 PM: ____ldr is in use. It will be removed on reboot.
1:21 PM: Quarantining All Traces: trojan-backdoor-haxdoor
1:21 PM: Quarantining All Traces: nvdialer
1:21 PM: Quarantining All Traces: military cookie
1:35 PM: Removal process completed. Elapsed time 00:25:36
********
12:30 PM: | Start of Session, Tuesday, 28 February 2006 |
12:30 PM: Spy Sweeper started
12:31 PM: Your spyware definitions have been updated.
12:33 PM: | End of Session, Tuesday, 28 February 2006 |

Sorry for the log result list but it has all the info on it.

while doing this tho 'Windows Installer …..XP with Front Page' window came up with 'Error 2203 - internal error C:\Windows\Installer\2af16.ipi - 2147287035…………did a bit more and came up with another three messages of the same but with different file numbers..tho the 214 etc. number was the same. Do I need to do anything to fix this ???

Back with an Edit…..
Forgot to add a HJT scan…..Logfile of HijackThis v1.99.1
Scan saved at 11:37:22 PM, on 28/02/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Barbara\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122263461303
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37610.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

My computer is working ok, sometimes takes a while to load up the programmes but I always blame the fact that I have in C:\ 12.6Gig Hard Drive, 1.28GB in E:\, thought it was a 15Gig altogether tho, bought it a couple of years ago now from a friend of a friend, he did one thing that confused me tho, he re-formatted it and put my name in as the owner - as he didn't want his name in the computer and told me not to go on to the Windows Update page as it won't recognise my name, is this true ?????

Thank you again for helping

Regards
Barb
Did you reboot before posting the new HJT log?

I know nothing about Front Page, sorry.


he re-formatted it and put my name in as the owner - as he didn't want his name in the computer and told me not to go on to the Windows Update page as it won't recognise my name, is this true

Doesn't sound like to me you have a licensed copy of Windows. Guess you'll find out when you try to run the updates.
Hello LDTate

Yes I did reBoot, but have just reBooted and done another HJT log.

On re-starting, the Windows Insallation window opens and shows the same message (it has something to do with Office) as before but with different .ipi files missing, the window for Messenger comes up too, when I opened OE,it says it is having problems and has to close, tho I haven't used Messenger for a long time now, how do I fix that tho ?

I am no longer getting the virus alerts from AVG, which must be a good sign !! Thank you !

I also rang my friend to find out about the computer, she has lost contact with the fellow that sold me the computer, he moved up to Perth …I'm in Australia.

Anyway, is there anything I can do about the name thing as I bought this computer in good faith, he just said he didn't want his name on the computer as the owner when it wasn't his any more !!!

I thought it was pretty good having my name on it as the registered owner…..feel pretty silly now tho !!

The cookie from the military that was found, is from a newletter that my daughter has been getting ever since she met one of your navy guys that called into our port, they were going to send emails to each other but it fizzled.

Logfile of HijackThis v1.99.1
Scan saved at 10:00:40 AM, on 1/03/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\msiexec.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Barbara\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122263461303
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37610.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

Thank you again for all the help and hope you have some answers for me or at least where I can find out about the name thing.

Regards
Barb

On re-starting, the Windows Insallation window opens and shows the same message (it has something to do with Office) as before but with different .ipi files missing, the window for Messenger comes up too, when I opened OE,it says it is having problems and has to close, tho I haven't used Messenger for a long time now, how do I fix that tho ?


1. My thoughts on that would be to re-install Office.
2. OE? Do you mean IE (internet Explorer)?
3. You can use Add/Remove Programs and remove Messenger if you want.


I also rang my friend to find out about the computer, she has lost contact with the fellow that sold me the computer, he moved up to Perth …I'm in Australia.

Anyway, is there anything I can do about the name thing as I bought this computer in good faith, he just said he didn't want his name on the computer as the owner when it wasn't his any more !!!

If you can get windows updates then Windows is legit, so everything is OK.





Please do not delete anything unless instructed to.

Unless you plan on purchasing these: (They are only 14 day trial versions)
Use Add/Remove Programs and remove: If listed.
ewido
Spy Sweeper



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://www.lizardtech.com/download/files/w…ntrol_en_US.cab


Close ALL windows and browsers except HijackThis and click "Fix checked"

Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
Hello
Here is my HJT Log, I deleted the two files that you noted.

I tried to remove Messenger 6.2 from the Add\Remove Programmes but it said it couldn't install it ..(I clicked the remove button so don't understand this one)… as there was an error 2203….the same error number as it showed for the Configuring XP for Front Page.

You asked
2. OE? Do you mean IE (internet Explorer)?
I was opening Outlook Express when Messenger put the message up to say it was going to close…… sorry, should have written the full name or explained it better.

As far as Ewido and SpySweeper are concerned…..I have Ad-aware, Spybot and AVG for my anti-virus (the free version) as this combination was recommended on one of the forum logs, would I be better either getting the full version of AVG or would Ewido or Spy do a better job at protecting my computer against this happening again.

Can you tell me what brought the Haxdoor Trojan to my maching in the first place???

I will install Office again, in the morning tho, it's nearly midnight now.
The computer seems to be ok, I went into a few of the programes and played a couple of the games and all seems to be fine.

On one of the posts it said that 020 WinLogon Notify: should not be there - I still have an 020 on my HJT log, is this ok to leave there ?

Thank you again for all your help, I really appreciate this new learning curve that I have experienced, tho I don't think I would like to do it again in a hurry !

Regards
Barb

Logfile of HijackThis v1.99.1
Scan saved at 11:12:25 PM, on 1/03/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\OptusNet DSL Internet\DSC.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\msiexec.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Barbara\Local Settings\Temp\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://dsl.optusnet.com.au/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by OptusNet
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [Desktop Service Centre] C:\Program Files\OptusNet DSL Internet\DSC.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [LWBMOUSE] C:\Program Files\Tech\Wheel Mouse\5.2\MOUSE32A.EXE
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://dsl.optusnet.com.au/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1122263461303
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061…all/xscan53.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37610.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe

Thanks again !!

tried to remove Messenger 6.2 from the Add\Remove Programmes but it said it couldn't install it ..(I clicked the remove button so don't understand this one)… as there was an error 2203….the same error number as it showed for the Configuring XP for Front Page.

You can try to install Messenger, then uninstall it.

You asked
2. OE? Do you mean IE (internet Explorer)?
I was opening Outlook Express when Messenger put the message up to say it was going to close…… sorry, should have written the full name or explained it better.

You might be able to do a Google Search and find the answer.

As far as Ewido and SpySweeper are concerned…..I have Ad-aware, Spybot and AVG for my anti-virus (the free version) as this combination was recommended on one of the forum logs, would I be better either getting the full version of AVG or would Ewido or Spy do a better job at protecting my computer against this happening again.

I use the same free ones you do along with SpywareBlaster. I'll post those later and you can decide. Both Ewido and SpySweeper are good but you have to purchase them after the 14 day trial ends.

Can you tell me what brought the Haxdoor Trojan to my maching in the first place???


I would suggest you read this:
So how did I get infected in the first place?
by Tony Klein


On one of the posts it said that 020 WinLogon Notify: should not be there - I still have an 020 on my HJT log, is this ok to leave there ?

No. That key os OK.O20 - Winlogon Notify: WRNotifier

How are we doing now?
Hello again I'm not really worried about Messenger, so will leave that topic. Protecting my computer: I will stay with the ones I have then, although I have been unable to update Ad-Aware for a while now and AVG has been so good. Will wait for the link to SpywareBlaster. I have a lot of fixes on my desktop at the moment, ie Vcleaner, CWShredder, Vundo Fix etc, do I leave them there for later use.?…….hopefully not …..but there's always some jerk out there sending those trojan's isn't there ! One problem I have now is Windows Media Player 10 - it says 'the specified module could not be found' so went to Add/Rem prog and clicked removed, but it rolled it back to version 8…..it still won't work. I can see me having to format the C:\ and start again !! Windows Installer comes up every time I re-start the computer and runs the same error messages for the ipi files - haven't re-installed Office yet tho, so that might fix that problem. Ran a Disk Clean up again and restarted, Word, Excel etc, take a long time to load but they work ok, as does Outlook Express, but I have about 100 unread emails downloaded but not read….with all the trouble I've had, not game to stay on line for long, just post here and get off !! I think now tho I will have to go to a Technician to fix the rest up….what do you think ??? Thank you for all your help looking forward to your reply Regards Barb

I have a lot of fixes on my desktop at the moment, ie Vcleaner, CWShredder, Vundo Fix etc, do I leave them there for later use.?…….

You can remove those.


Note: This will remove all previous Restore Points

Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

Restart your computer, turn it back on.

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Remove the Check Turn off System Restore.
Click Apply, and then click OK.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Check "Hide file extensions for known file types."
Under the "Hidden files" folder, Uncheck "Show hidden files and folders."
Check "Hide protected operating system files."
Click Apply, and then click OK.





If you dont have these three programs I would recommend that you get them. Spywareblaster, Spywareguard and IESPY AD. They will add 1000's of sites to your resticted zone and block some hijacks from happening. I also have a FREE FIREWALL and FREE ANTI VIRUS if you need one.

It is critical to have both a firewall and anti virus to protect your system.

Keep your system up to date and run Adaware & Spybot, once a week works, and hopefully you will be ok from here on. Both are available below.

Safe Surfing. :D

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI