This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

about:blank

30 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday afternoon I started getting a "new" homepage, without me doing anything. It starts with "about:blank" and then automatically flips to "www,securityuptodate.net" where there are many adverisements for products such as "Pest Trap" and "Brave Sentry". I don't think these are legit or they wouldn't have to go the the extent of forcing there site onto my computer as a home page. I also have an icon in the lower right corner of the computer screen (beside the clock) that pops up to tell me that I have 4 adware and spyware programs that are active on my computer. There's no way to shut it off, but when I double click on it, it opens a window at "http://virusblast.com/?aid=7". I've also had other program pages pop up here too.

Here's my Logfile from HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 00.32.10, on 31/05/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\atmclk.exe
C:\WINDOWS\system32\dcomcfg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
E:\Microsoft Office\OFFICE11\OUTLOOK.EXE
K:\Downloaded Software\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.microsoft.com
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Nothing - {f79fd28e-36ee-4989-aa61-9dd8e30a82fa} - C:\WINDOWS\system32\hp100.tmp
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Eclipse] "C:\Program Files\Java\j2re1.4.1_02\bin\javaw" -Djava.library.path=C:\Progra~1\eclipse -jar C:\Progra~1\eclipse\eclipse.jar
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\AdwareFilter.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147359044722
O17 - HKLM\System\CCS\Services\Tcpip\..\{73E8ADF2-6FA2-480D-8450-601C026018F8}: NameServer = 199.166.6.2 209.239.11.98
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe

I can only hope that you can help and thank you for your knowledge and your efforts.
Hello M1ck3Y and welcome to the TomCoyote,

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

______________________________

Please download the trial version of Ewido anti-malware 3.5 from here:
http://www.ewido.net/en/download/
  • Install Ewido anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please post:
C:\rapport.txt
Here's the rapport.txt file, and thank you SmitFraudFix v2.53 Scan done at 0.34.23.79, 01/06/2006 Run from C:\Documents and Settings\Lyle\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\dcomcfg.exe FOUND ! C:\WINDOWS\system32\hp???.tmp FOUND ! C:\WINDOWS\system32\hp????.tmp FOUND ! C:\WINDOWS\system32\ld????.tmp FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\simpole.tlb FOUND ! C:\WINDOWS\system32\stdole3.tlb FOUND ! C:\WINDOWS\system32\ts.ico FOUND ! C:\WINDOWS\system32\1024\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Lyle\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Lyle\FAVORI~1 C:\DOCUME~1\Lyle\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{0c7416f0-dd23-420f-97f5-aae352ea2bf1}"="glochid" [HKEY_CLASSES_ROOT\CLSID\{0c7416f0-dd23-420f-97f5-aae352ea2bf1}\InProcServer32] @="C:\WINDOWS\system32\wfkduei.dll" [HKEY_CURRENT_USER\Software\Classes\CLSID\{0c7416f0-dd23-420f-97f5-aae352ea2bf1}\InProcServer32] @="C:\WINDOWS\system32\wfkduei.dll" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Thank you M1ck3Y,

Now do the following:

Clean

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]


The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close Ewido and Reboot in Normal Mode.
______________________________

Please post:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Susan: Thank you for your help. I need to explain the way my computer is configured a bit, to help you with your diagnosis. I have 2 hard drives (80GB and 120GB). The 80 has win 2000 Pro installed as the operating system, and the 120 has win XP Pro, but I have access to all the files from either system (but I have the instal the software on both OS's to access it from both.) I noticed while using ewido that most of the errors were coming from the 80, that I really don't use very much, so I suspect they've been there for over 2 years. Then I saw a "*.tmp" file show up, and I realized that I hadn't gone into 2000 to remove the temp files from that aprt of the system. So I cancelled the scan, then cleaned everything, then rescanned the whole system from the 120, then I scanend the whole system from the 80. So you will get 3 ewido scan reports and 1 from SmitfraudFix. Thanks again. SmitFraudFix v2.53 Scan done at 9.35.31.31, 01/06/2006 Run from C:\Documents and Settings\Lyle\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{0c7416f0-dd23-420f-97f5-aae352ea2bf1}"="glochid" [HKEY_CLASSES_ROOT\CLSID\{0c7416f0-dd23-420f-97f5-aae352ea2bf1}\InProcServer32] @="C:\WINDOWS\system32\wfkduei.dll" [HKEY_CURRENT_USER\Software\Classes\CLSID\{0c7416f0-dd23-420f-97f5-aae352ea2bf1}\InProcServer32] @="C:\WINDOWS\system32\wfkduei.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\dcomcfg.exe Deleted C:\WINDOWS\system32\hp???.tmp Deleted C:\WINDOWS\system32\ld????.tmp Deleted C:\WINDOWS\system32\ot.ico Deleted C:\WINDOWS\system32\simpole.tlb Deleted C:\WINDOWS\system32\stdole3.tlb Deleted C:\WINDOWS\system32\ts.ico Deleted C:\WINDOWS\system32\1024\ Deleted C:\DOCUME~1\Lyle\FAVORI~1\Antivirus Test Online.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri C:\WINDOWS\system32\wfkduei.dll -> Missing File »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 11.46.36, 01/06/2006 + Report-Checksum: F29E0B78 + Scan result: HKU\S-1-5-21-507921405-1972579041-682003330-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F79FD28E-36EE-4989-AA61-9DD8E30A82FA} -> Trojan.Small : Cleaned with backup :mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.17:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup :mozilla.9:C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup C:\Documents and Settings\Lyle\Cookies\[removed][2].txt -> TrackingCookie.Dbbsrv : Cleaned with backup C:\RECYCLER\NPROTECT\00000061.TXT -> TrackingCookie.2o7 : Cleaned with backup C:\RECYCLER\NPROTECT\00000062.TXT -> TrackingCookie.2o7 : Cleaned with backup C:\RECYCLER\NPROTECT\00000065.TXT -> TrackingCookie.2o7 : Cleaned with backup C:\RECYCLER\NPROTECT\00000066.TXT -> TrackingCookie.2o7 : Cleaned with backup :mozilla.14:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.25:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.32:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.35:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.38:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.39:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.40:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.41:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.42:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.44:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.46:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.49:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.50:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.51:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.53:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup :mozilla.54:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.55:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.57:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.58:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.59:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.60:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.61:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.62:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.87:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.92:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.104:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.105:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup :mozilla.106:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.109:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.110:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.120:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup :mozilla.121:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup :mozilla.123:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.139:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.141:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup :mozilla.146:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.148:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.150:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.151:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.158:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.170:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.171:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.173:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.174:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.181:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.182:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup :mozilla.185:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.186:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.187:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.191:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.192:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.194:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.195:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.197:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.198:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.200:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup :mozilla.201:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.205:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.206:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.209:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.214:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.220:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.224:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup :mozilla.225:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.228:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.234:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.244:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.245:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.246:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.247:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.250:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.251:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.254:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.255:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.259:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.260:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.261:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.263:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.264:H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup H:\ecommerce\dialer.exe -> Heuristic.Win32.Dialer : Cleaned with backup ::Report End ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 15.32.18, 01/06/2006 + Report-Checksum: 19CE6F91 + Scan result: No infected objects found. ::Report End ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 18:19:29, 01.06.2006 + Report-Checksum: 7B5D2074 + Scan result: No infected objects found. ::Report End
Susan: Here's the file you've requested. I don't know the precise rules of the forum, but I've found an anti-virus program called NOD32 by a company called Eset. It sems to be good program, but I'd appreciate any comments you may have. I routinely run (or will from now on) Spybot S&D and AdAware SE Personal. Should I also run Ewido and can you recommend a "great" firewall?

Now for the report:

Logfile of HijackThis v1.99.1
Scan saved at 23.39.43, on 01/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
K:\Downloaded Software\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lmcnair.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Eclipse] "C:\Program Files\Java\j2re1.4.1_02\bin\javaw" -Djava.library.path=C:\Progra~1\eclipse -jar C:\Progra~1\eclipse\eclipse.jar
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\AdwareFilter.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147359044722
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls


Test your Firewall - Please test your firewall and make sure it is working properly.
Test Firewall

Update your Java to the latest version. Uninstall any and all versions you have listed in add/remove programs and install the latest version from here:
https://sdlc6c.sun.com/ECom/EComActionServl…4E1EA2D176EE3EA

I like ewido since we take advantage of their free trial and have posters use it frequently. It is a complement to an anti-virus program. Can you run ewido on your drive with Windows 2000?

The below applies to the hijackthis log of your XP drive.


Disable Microsoft Windows Defender:
We need to disable your Microsoft Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
  • Open Microsoft Windows Defender. Click Start, Programs, Windows Defender
  • Click on Tools, General Settings.
  • Under Real-time protection options, unselect the Turn on real-time protection check box
  • Click Save
After all of the fixes are complete it is very important that you enable Real-time Protection again.

Please set your system to show all files; please see here if you're unsure how to do this.

Scan with HijackThis. Place a check against each of the following:
O2 - BHO: Nothing - {6ab7158b-4bff-4160-ad7d-4d622df548cf} - C:\WINDOWS\system32\hp100.tmp (file missing)
O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\AdwareFilter.exe
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - E:\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
O4 - Global Startup: AdwareFilter Background Protection.lnk = C:\Program Files\AdwareFilter\<==folder
Exit Explorer, and reboot as normal afterwards.

Post back a fresh HijackThis log and we will take another look.
Susan: I've ben able to do everything down to the step using "Windows Explorer". I cannot find any reference to "Global Startup" on the computer, and if you want me to delete the file beginning with "C:\Program Files\AdwareFilter\…" it doesn't exist. I do have a file called "C:\Program Files\AdwareFilter-savelogs\… As well, the "04" reference is something in HijackThis. I ran HijackThis in "Safe Mode" and there is no line there that resembles the one you provided. Sorry, but I'm lost. The last of the Ewido files that I sent you was run on the Windows 2000 pro side of the computer, and it was clear.
Sorry about that. It may not exist, but it is better to ask you to find and delete it and it not exist than to not ask you to find and delete it and it does exist. I need to add that it may not exist. Please do reply with another hijackthis log.
Susan:

Here's the HijackThis file. I'm about to re-enable the Windows Defender; any cautions?

You may note that I've installed "Retrospect" by Lavasoft as my firewall program, and when I tested it using your test, everything came up clean.

Logfile of HijackThis v1.99.1
Scan saved at 00.31.14, on 06/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
K:\Downloaded Software\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lmcnair.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Eclipse] "C:\Program Files\Java\j2re1.4.1_02\bin\javaw" -Djava.library.path=C:\Progra~1\eclipse -jar C:\Progra~1\eclipse\eclipse.jar
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Personal Firewall] C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147359044722
O20 - AppInit_DLLs: C:\PROGRA~1\Lavasoft\PERSON~1\wl_hook.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Personal Firewall Service (LavasoftFirewall) - Agnitum Ltd. - C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\rthlpsvc.exe
M1ck3Y your hijackthis log appears to be clean.

Let's run one more scan please. Then if it is clean I will give you the final instructions.

Now run this online scan using Internet Explorer:
Kaspersky WebScanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Anti-Virus Web Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your reply please.
Susan: Here's the Kaspersky file and I've also run NOD32 again, so that file is below Kaspersky: Is the fact that Kaspersky found viruses that NOD32 did not pick up mean that Kaspersky is better, or just that NOD32 was already used and the system had been "cleaned", so there shouldn't be any new viruses for it to find? I haven't yet removed any of the viruses that Kaspersky found. Just ran the report at this time. ——————————————————————————- KASPERSKY ON-LINE SCANNER REPORT Tuesday, June 06, 2006 6:40:10 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.78.0 Kaspersky Anti-Virus database last update: 6/06/2006 Kaspersky Anti-Virus database records: 186696 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ F:\ G:\ H:\ I:\ J:\ K:\ Scan Statistics: Total number of scanned objects: 206046 Number of viruses found: 12 Number of infected objects: 22 Number of suspicious objects: 12 Duration of the scan process: 03:04:04 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]][Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]][Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\3E9N2BBI\indexit[1].htm Infected: Exploit.HTML.Mht skipped C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\61ALTP7V\indexa[1].htm Infected: Exploit.HTML.Mht skipped C:\Program Files\ESET\infected\2FEEC2CA.NQF Infected: Trojan-Downloader.Win32.Zlob.qi skipped C:\Program Files\ESET\infected\D5DDKECA.NQF Infected: Trojan-Downloader.Win32.Zlob.qm skipped C:\Program Files\ESET\infected\IIIIQQCA.NQF Infected: Trojan-Downloader.Win32.Zlob.qm skipped C:\Program Files\ESET\infected\LAL10BAA.NQF Infected: Trojan-Downloader.Win32.Zlob.qr skipped C:\Program Files\ESET\infected\UXEWWRAA.NQF Infected: not-virus:Hoax.Win32.Renos.cw skipped C:\Program Files\Norton SystemWorks\Norton Antivirus\Quarantine\043277E4 Infected: Exploit.HTML.Mht skipped C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP879\A0105649.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP880\A0106649.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP881\A0106660.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Deleted Items/03 Mar 2004 00:21 from [removed]:Re: Re: Message/message_details.pif Infected: Email-Worm.Win32.NetSky.d skipped H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Deleted Items/02 Mar 2004 21:25 from [removed]:Re: Approved/all_document.pif Infected: Email-Worm.Win32.NetSky.d skipped H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Mail MS Mail: infected - 2 skipped H:\WINNT\system32\task32a.exe/nt32.ini Infected: IRC-Worm.IRC.Froze skipped H:\WINNT\system32\task32a.exe/gg.bat Infected: Backdoor.IRC.Cloner.g skipped H:\WINNT\system32\task32a.exe/httpsearch.ini Infected: Backdoor.IRC.Cloner.g skipped H:\WINNT\system32\task32a.exe/dll32NT.hlp Infected: Backdoor.IRC.Cloner skipped H:\WINNT\system32\task32a.exe/xvpll.hlp Infected: Backdoor.IRC.Cloner.q skipped H:\WINNT\system32\task32a.exe/taskmngr.exe Infected: Backdoor.Win32.mIRC-based skipped H:\WINNT\system32\task32a.exe ViseMan: infected - 6 skipped H:\WINNT\system32\task32a.exe ViseMan: infected - 6 skipped K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]][Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>][Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>][Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped K:\Users\lmcnair\Mail\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped Scan process completed. **************************************************** Scan performed at: 06/06/2006 06.46.05 Scanning Log NOD32 version 1.1581 (20060606) NT Operating memory - is OK Date: 6.6.2006 Time: 06:46:12 Scanned disks, folders and files: C:; E:; F:; G:; H:; I:; J:; K: C:\hiberfil.sys - error opening (File locked) [4] C:\pagefile.sys - error opening (File locked) [4] C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp - error opening (Access denied) [4] C:\Documents and Settings\LocalService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\LocalService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Lyle\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\Lyle\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\Lyle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\Lyle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\NTUSER.DAT - error opening (File locked) [4] C:\Documents and Settings\NetworkService\ntuser.dat.LOG - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat - error opening (File locked) [4] C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG - error opening (File locked) [4] C:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB824141$\user32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB824141$\win32k.sys - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826939$\hhsetup.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826939$\itss.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826939$\sysmain.sdb - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826939$\winsrv.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\dhcpcsvc.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\ndis.sys - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\ndisuio.sys - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\netshell.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\wzcdlg.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\wzcsapi.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB826942$\wzcsvc.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828028$\msasn1.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\colbact.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\comuid.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\es.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\ole32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB828741$\txflog.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\dao360.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\expsrv.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msexch40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msexcl40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjet40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjetol1.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjetoledb40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjint40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjter40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msjtes40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msltus40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\mspbde40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msrd2x40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msrd3x40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msrepl40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\mstext40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\mswdat10.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\mswstr10.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\msxbde40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB829558$\vbajet32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB833330$\Blastcln\blastcln.exe - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB833407$\bssym7.ttf - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\callcont.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\h323.tsp - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\msgina.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\mst120.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\schannel.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB835732$\xpsp2res.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\dao360.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\msjetol1.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB839645$\fldrclnr.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB839645$\shell32.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB839645$\shlwapi.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB839645$\sxs.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallKB839645$\xpsp2res.dll - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallQ828026$\msdxm.ocx - error opening (Access denied) [4] C:\WINDOWS\$NtUninstallQ828026$\wmpcore.dll - error opening (Access denied) [4] C:\WINDOWS\system32\CatRoot2\edb.log - error opening (File locked) [4] C:\WINDOWS\system32\CatRoot2\tmp.edb - error opening (File locked) [4] C:\WINDOWS\system32\config\default - error opening (File locked) [4] C:\WINDOWS\system32\config\default.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\SAM - error opening (File locked) [4] C:\WINDOWS\system32\config\SAM.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\SECURITY - error opening (File locked) [4] C:\WINDOWS\system32\config\SECURITY.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\software - error opening (File locked) [4] C:\WINDOWS\system32\config\software.LOG - error opening (File locked) [4] C:\WINDOWS\system32\config\system - error opening (File locked) [4] C:\WINDOWS\system32\config\system.LOG - error opening (File locked) [4] C:\WINDOWS\Temp\JET9A47.tmp - error opening (File locked) [4] E:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] F:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] G:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] H:\Documents and Settings\Lyle McNair\Application Data\Mozilla\Profiles\lyle\wnfenc1p.slt\Mail\pop3.norton.antivirus\Trash »MIME » - error occurred while reading archive H:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] I:\Office\Templates\RLP-RCR TR.dot - error opening (Access denied) [4] I:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] J:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] K:\System Volume Information\MountPointManagerRemoteDatabase - error opening (Access denied) [4] Number of scanned files: 207573 Number of threats found: 0 Time of completion: 07:41:12 Total scanning time: 3300 sec (00:55:00) Notes: [4] File cannot be opened. It may be in use by another application or operating system. ******************************************
Hello M1ck3y,

The following refer to emails so you need to delete them. It looks like there are some duplicate entries referring to the same emails.

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]

[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]]
[Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped

C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped

C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped

C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped

C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]]
[Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped

C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped

C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped
===================================
C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\Mail\mail.lylemcnair.com\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped

H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Deleted Items/03 Mar 2004 00:21 from [removed]:Re: Re: Message/message_details.pif Infected: Email-Worm.Win32.NetSky.d skipped
H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst/Personal Folders/Deleted Items/02 Mar 2004 21:25 from [removed]:Re: Approved/all_document.pif Infected: Email-Worm.Win32.NetSky.d skipped
H:\Documents and Settings\Lyle McNair\Local Settings\Application Data\Microsoft\Outlook\outlook.pst Mail MS Mail: infected - 2 skipped


K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text/[From [removed]]
[Date Thu, 22 Feb 2001 00:12:09 -0800]/html Suspicious: Exploit.HTML.SecurityBreach.3 skipped

K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text/[From Lyle McNair <[removed]>]
[Date Sat, 17 Feb 2001 18:47:47 -0500]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped

K:\Users\lmcnair\Mail\Lyle.sbd\Misc/[From WadeWhimsies Moderator <[removed]>]
[Date 30 Jan 2001 07:07:22 -0000]/text Suspicious: Exploit.HTML.SecurityBreach.3 skipped

K:\Users\lmcnair\Mail\Lyle.sbd\Misc Mail Berkeley mbox: suspicious - 3 skipped
Please download ATF Cleaner by Atribune.
======================
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Please download The Avenger by Swandog46 to the Desktop.
Click on Avenger.zip to open the file
Then, extract avenger.exe to the Desktop

Next, copy all the blue text below to the Clipboard by highlighting it and pressing Ctrl+C:

Files to delete:
C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\3E9N2BBI\indexit[1].htm
C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\61ALTP7V\indexa[1].htm
C:\Program Files\ESET\infected\2FEEC2CA.NQF
C:\Program Files\ESET\infected\D5DDKECA.NQF
C:\Program Files\ESET\infected\IIIIQQCA.NQF
C:\Program Files\ESET\infected\LAL10BAA.NQF
C:\Program Files\ESET\infected\UXEWWRAA.NQF
H:\WINNT\system32\task32a.exe



Start The Avenger program by clicking its icon on the Desktop.
Under: Script file to execute, select: Input Script Manually
Now click on the Magnifying Glass icon
It opens a new window titled: View/edit script
Paste the text copied to clipboard into this window by pressing Ctrl+V.
Click Done

Next, click on the Green Light to begin the execution of the script
Answer Yes twice when prompted.

The Avenger automatically does following:
Restarts the computer.
On reboot, briefly opens a black command window on the Desktop. This is normal.

After the restart, it creates a log that opens with the results of Avenger’s actions.
This log is located at C:\avenger.txt


Don'r worry about the _restore files—we will take care of those later.

Please run the Kapersky scan again.
Post the C:\avenger.txt, the results from Kapersky, and a new hijackthis log in your reply.
Susan:

Sorry for the length of time this is taking. Finding the e-mails was a major undertaking. Netscape has a quirk to it in that even though you've deleted a file, it's still there and readable with the file system until you've "compacted the folders". The program, at least as I have it set up, doesn't do that automatically, and since I haven't used Netscape for over 2 years, there were messages that I had deleted long ago that were still showing up. Finally a light went on! Empty all the trash, compact the folders, and empty the Recycle bins. After that was completed, I've run the programs as directed, but I was unable to have any impact on the top 2 lines of file names with Avenger.

Regardless, here are all the files you requested, but it seems as though we're adding faster than we're removing. Regards and thank you.

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\oxjekpmk

*******************

Script file located at: \??\C:\Program Files\wjnowvqa.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Could not open file C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\3E9N2BBI\indexit[1].htm for deletion
Deletion of file C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\3E9N2BBI\indexit[1].htm failed!

Could not process line:
C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\3E9N2BBI\indexit[1].htm
Status: 0xc000003a



Could not open file C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\61ALTP7V\indexa[1].htm for deletion
Deletion of file C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\61ALTP7V\indexa[1].htm failed!

Could not process line:
C:\Documents and Settings\Lyle\Local Settings\Temp\Temporary Internet Files\Content.IE5\61ALTP7V\indexa[1].htm
Status: 0xc000003a

File C:\Program Files\ESET\infected\2FEEC2CA.NQF deleted successfully.
File C:\Program Files\ESET\infected\D5DDKECA.NQF deleted successfully.
File C:\Program Files\ESET\infected\IIIIQQCA.NQF deleted successfully.
File C:\Program Files\ESET\infected\LAL10BAA.NQF deleted successfully.
File C:\Program Files\ESET\infected\UXEWWRAA.NQF deleted successfully.
File H:\WINNT\system32\task32a.exe deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, June 07, 2006 4:02:11 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.78.0
Kaspersky Anti-Virus database last update: 7/06/2006
Kaspersky Anti-Virus database records: 187073
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan Statistics:
Total number of scanned objects: 193396
Number of viruses found: 9
Number of infected objects: 24
Number of suspicious objects: 0
Duration of the scan process: 02:53:44

Infected Object Name / Virus Name / Last Action
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/2FEEC2CA.NQF Infected: Trojan-Downloader.Win32.Zlob.qi skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/D5DDKECA.NQF Infected: Trojan-Downloader.Win32.Zlob.qm skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/IIIIQQCA.NQF Infected: Trojan-Downloader.Win32.Zlob.qm skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/LAL10BAA.NQF Infected: Trojan-Downloader.Win32.Zlob.qr skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/UXEWWRAA.NQF Infected: not-virus:Hoax.Win32.Renos.cw skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/nt32.ini Infected: IRC-Worm.IRC.Froze skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/gg.bat Infected: Backdoor.IRC.Cloner.g skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/httpsearch.ini Infected: Backdoor.IRC.Cloner.g skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/dll32NT.hlp Infected: Backdoor.IRC.Cloner skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/xvpll.hlp Infected: Backdoor.IRC.Cloner.q skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe/taskmngr.exe Infected: Backdoor.Win32.mIRC-based skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip/avenger/task32a.exe Infected: Backdoor.Win32.mIRC-based skipped
C:\avenger\backup-07.06.2006-12.52.23.31.zip ZIP: infected - 12 skipped
C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP879\A0105649.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped
C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP880\A0106649.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped
C:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP881\A0106660.tlb Infected: Trojan-Downloader.Win32.Zlob.qm skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/nt32.ini Infected: IRC-Worm.IRC.Froze skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/gg.bat Infected: Backdoor.IRC.Cloner.g skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/httpsearch.ini Infected: Backdoor.IRC.Cloner.g skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/dll32NT.hlp Infected: Backdoor.IRC.Cloner skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/xvpll.hlp Infected: Backdoor.IRC.Cloner.q skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe/taskmngr.exe Infected: Backdoor.Win32.mIRC-based skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe ViseMan: infected - 6 skipped
H:\System Volume Information\_restore{F3497D04-5D5D-4BFB-8A0C-8DEB64106B34}\RP906\A0109925.exe ViseMan: infected - 6 skipped

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 16.04.45, on 07/06/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
K:\Downloaded Software\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lmcnair.com/
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Lyle\Application Data\Mozilla\Profiles\default\hlzvw1gf.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Eclipse] "C:\Program Files\Java\j2re1.4.1_02\bin\javaw" -Djava.library.path=C:\Progra~1\eclipse -jar C:\Progra~1\eclipse\eclipse.jar
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Personal Firewall] C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe /waitservice
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = E:\Adobe\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1147359044722
O17 - HKLM\System\CCS\Services\Tcpip\..\{73E8ADF2-6FA2-480D-8450-601C026018F8}: NameServer = 199.166.6.2 209.239.11.98
O20 - AppInit_DLLs: C:\PROGRA~1\Lavasoft\PERSON~1\wl_hook.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lavasoft Personal Firewall Service (LavasoftFirewall) - Agnitum Ltd. - C:\Program Files\Lavasoft\Personal Firewall\lpfw.exe
O23 - Service: NMSAccess - Unknown owner - C:\Program Files\Cheetah Burner\Cheetah CD Burner\NMSAccess.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\retrorun.exe
O23 - Service: Retrospect Helper - EMC Corporation - C:\Program Files\Retrospect\Retrospect 7.5\rthlpsvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI