This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

there's some kind of spyware in my system......

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 5:07:32 PM, on 11/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\DOCUME~1\Jason\LOCALS~1\Temp\li.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jason\Desktop\stuff to clean the computer\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jason\Application Data\Mozilla\Profiles\default\7uuk8bnm.slt\prefs.js)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Bowmans Poker Room - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BOWMAN~1\client.exe (file missing)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 4.0.0.320 - http://63.102.226.240:8000/Java/cfs40320.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131419283531
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned35.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: Adobe Acrobat 5.0 - {10EE3672-C265-2E74-4E09-E178B429A706} - c:\program files\adobe\acrobat 5.0\reader\ufomfn32.dll (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Hello jayfan41 and Welcome to TomCoyote,

Nothing stands out in your hijackthis log.
Scan with HijackThis. Place a check against each of the following:
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Let run a few scans please.
Now run this online scan using Internet Explorer:
Kaspersky Online Scanner from http://www.kaspersky.com/virusscanner

Next Click on Launch Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Standard
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan:
  • Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
Copy and paste that information from Kapersky in your next post.


Download Gmer from here:
http://www.gmer.net/gmer.zip
  • Disconnect from internet and close running programs.
  • There is a small chance this app may crash your computer so save any work you have open.
  • Double click gmer.exe
  • Let the gmer.sys driver load if asked.
  • If it gives you a warning at program start about rootkit activity and asks if you want to run scan…say Ok.
  • If no warning….
  • Click "rootkit" tab and click "scan"
  • Once done click "copy"
  • Open Notepad and hit "ctrl+v" to paste log.
  • Reconnect to internet and post log please.
Please tell me what you are experiencing.
On your next reply, please include:
  • Kapersky log
  • gmer log
Thanks for your prompt reply……..below you will find the 2 scans that you requested I do……….another question I have (and I don't know if this issue is legit or not), but very recently, I receive a message at the bottom right of my screen which says "Windows - System Error…..There is an IP address conflict with another system on the network"……….when this message comes up, I am disconnected from the internet from anywhere from 2-5 minutes. Does this have to do with infections in the system?
Thanks again greatly……

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 04, 2006 3:56:45 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/11/2006
Kaspersky Anti-Virus database records: 224729
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 113272
Number of viruses found: 11
Number of infected objects: 24 / 0
Number of suspicious objects: 5
Duration of the scan process: 00:56:52

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip/somaticCAB.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Francine\Local Settings\Temp\II22.exe/data0002 Infected: Trojan-Proxy.Win32.Agent.d skipped
C:\Documents and Settings\Francine\Local Settings\Temp\II22.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-42e537af-5f89f2cf.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-42e537af-5f89f2cf.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-42e537af-5f89f2cf.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-42e537af-5f89f2cf.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-10fccb28.zip/Counter.class Infected: Trojan.Java.ClassLoader.i skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-10fccb28.zip/VerifierBug.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-10fccb28.zip/Beyond.class Infected: Trojan.Java.ClassLoader.k skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-53b20017-10fccb28.zip ZIP: infected - 3 skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-2d1f118a-1b7a8543.zip/Installer.class Infected: Trojan-Downloader.Java.OpenStream.z skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-2d1f118a-1b7a8543.zip ZIP: infected - 1 skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-4ad49016.zip/GetAccess.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-4ad49016.zip/Installer.class Infected: Trojan-Downloader.Java.OpenConnection.aj skipped
C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-8fba448-4ad49016.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Jason\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\History\History.IE5\MSHist012006110420061105\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Temp\0v6nqmwk.wm Suspicious: Exploit.Win32.IMG-WMF skipped
C:\Documents and Settings\Jason\Local Settings\Temp\249p91en.exe/data0008 Infected: Trojan-Downloader.Win32.Zlob.wo skipped
C:\Documents and Settings\Jason\Local Settings\Temp\249p91en.exe NSIS: infected - 1 skipped
C:\Documents and Settings\Jason\Local Settings\Temp\249p91en.exe UPX: infected - 1 skipped
C:\Documents and Settings\Jason\Local Settings\Temp\249p91en.exe PE_Patch.UPX: infected - 1 skipped
C:\Documents and Settings\Jason\Local Settings\Temp\cz0qvam6.wm Suspicious: Exploit.Win32.IMG-WMF skipped
C:\Documents and Settings\Jason\Local Settings\Temp\hqdt4txh.wm Suspicious: Exploit.Win32.IMG-WMF skipped
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jason\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jason\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\AIM95\aim.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\q63629.exe Infected: Trojan-Downloader.Win32.Small.amb skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\SYSTEM32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\temp\ASHeuristic\loader[1]_exe.vir Infected: Trojan.Win32.SecondThought.ai skipped
C:\WINDOWS\temp\ASHeuristic\q63629_exe.vir Infected: Trojan-Downloader.Win32.Small.amb skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.



GMER 1.0.12.11879 - http://www.gmer.net
Rootkit scan 2006-11-04 04:10:38
Windows 5.1.2600 Service Pack 2


—- System - GMER 1.0.12 —-

SSDT \??\C:\Program Files\ewido\security suite\guard.sys ZwOpenProcess
SSDT \??\C:\Program Files\ewido\security suite\guard.sys ZwTerminateProcess

—- Kernel code sections - GMER 1.0.12 —-

.text ntoskrnl.exe!_abnormal_termination + 564 804E2890 4 Bytes
.text ntoskrnl.exe!_abnormal_termination + 1104 804E2AAC 4 Bytes

—- Files - GMER 1.0.12 —-

ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\A1SJ656T\602-3981058-6718246[1].:
ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\JY4J7X4T\104-0839462-1985517[1].:
ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\OZ7JMGL5\shop.runningroom[1].à:}
ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\OZ7JMGL5\shop.runningroom[2].à:}
ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\OZ7JMGL5\shop.runningroom[3].à:}
ADS C:\Documents and Settings\Francine\Local Settings\Temporary Internet Files\Content.IE5\OZ7JMGL5\shop.runningroom[4].à:}
ADS C:\Documents and Settings\Jason\Local Settings\Temp\~PIA5.jpg: SummaryInformation
ADS C:\Documents and Settings\Jason\Local Settings\Temp\~PIA5.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\Jason\Local Settings\Temp\~PIC0.jpg: SummaryInformation
ADS C:\Documents and Settings\Jason\Local Settings\Temp\~PIC0.jpg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}
ADS C:\Documents and Settings\Jason\Local Settings\Temp\~PID2.jpg: SummaryInformation
ADS …
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\ads[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\boxscore[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\0NX8CTXH\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\3O9DJK8C\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\452N0H6B\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4HIROH6F\mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4HIROH6F\schedule[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4HIROH6F\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4HIROH6F\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4HIROH6F\ShowFolder[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4TQ7416Z\1385[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4TQ7416Z\bio[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4TQ7416Z\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\4TQ7416Z\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\644[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\5Q8PD5Y5\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\6O9937RJ\bestwestern[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\MLB_20030919_CHC@PIT[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\splits[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\throwbaseball[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\85QN4LMJ\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\8810HVFR\boxscore[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\8810HVFR\images[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\8810HVFR\miniSB[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\8810HVFR\search[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\8810HVFR\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\boxscore[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\Compose[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\recap[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\AXHEARXE\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\CPE30TY3\news[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\CPE30TY3\scoreboard[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\G963C16Z\searchPlayerSearchServlet[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\G963C16Z\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\H1ZXM8JE\scoreboard[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\HF33PX8E\ads[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\HF33PX8E\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\HF33PX8E\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\Find_Person[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\instacompose[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\instacompose[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\instacompose[3].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\ShowFolder[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\splits[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\splits[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\throwbaseball[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\ISOSVSCH\xxl[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K5MVKLUZ\career[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K5MVKLUZ\cubs.mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\K5MVKLUZ\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\6327[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\career[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\gamelog[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\nba[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\players[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\players[3].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\pollData[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\reds.mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\scoreboard[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\scoreboard[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\throwbaseball[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\KBXNMM39\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\O9QN41UR\boxscore[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\O9QN41UR\ShowFolder[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\OHA7016F\yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\OHEV8XA7\6980[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\OHEV8XA7\fantasysports.yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\OHEV8XA7\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QDQPO1SF\boxscore[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QDQPO1SF\boxscore[1].: W
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QDQPO1SF\ShowLetter[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QDQPO1SF\throwbaseball[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QX9M7AXO\mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QX9M7AXO\players[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QX9M7AXO\players[2].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\QX9M7AXO\sports.yahoo[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\VYCJB14H\5766[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\VYCJB14H\mlb[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\WLYBOTEF\scoreboard[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\WTMJK5M7\scoreboard[1].:
ADS C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\WXAN4LI3\ShowLetter[1].:

—- EOF - GMER 1.0.12 —-
Thanks for the logs. Let's see if your message will go away after clearing up the infected files.

Please download ATF Cleaner by Atribune.

This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose:Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click
  • No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE:If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

==========================================
To delete the infected cache files
===================================
http://support.f-secure.com/enu/home/virus…javacache.shtml
How to Clean a Java Cache Folder
In some rare cases a few infected files and archives with infected files are detected inside Java cache folder. The location of this folder in your case is:

C:\Documents and Settings\Jason\Application Data\Sun\Java\Deployment\cache\
you will be deleting all files within cache folder but do not delete the cache folder

Removing infection
To empty the cache folder, access it with Windows Explorer. Select all files and subfolders and then press the "Delete" button on a keyboard, or select the File->Delete menu option. As this folder contains only cached files, no actual data is lost in the operation.

WARNING! Please be careful when deleting files. Make sure that you are deleting files only inside the Java cache folder, otherwise you may damage your system!

=================
AIM95 is AOL instant messenger. I would just uninstall AOL Instant Messenger
Make sure that this file is deleted after the uninstall
C:\Program Files\AIM95\aim.exe<=file
then download and install a fresh version AOL Instant Messenger again.

====================
I would just uninstall QuickTime and make sure that this file is deleted after the uninstall.
C:\Program Files\QuickTime\qttask.exe<=file
Then download and install a fresh version of QuickTime

Please set your system to show all files; please see here if you're unsure how to do this.

Reboot into Safe Mode: please see here if you are not sure how to do this.

Using Windows Explorer, locate the following files/folders, and delete them:
C:\q63629.exe<=file
C:\WINDOWS\temp\ASHeuristic\<=folder

Exit Explorer, and reboot as normal afterwards.

Please run Kapersky again and let's see how we did.
Hi there again, I did everything you requested me to do EXCEPT: 1.) couldn't delete Quicktime - the messgae I got was "Cannot delete qttask : Access is denied Make sure the disk is not full or write-protected and that the file is currently not in use" 2.) In safe mode, I couldn't locate C:\WINDOWS\temp\ASHeuristic - which meant, I obviously couldn't remove it I still believe there's something in my system…….even when I was running the new Kaspersky scan, (I did it in IE - my firefox browser popped up with some website (drivecleaner.com) telling me to download this - download that - which of course I didn't do Anyhow, here is the updated scan Thanks again for your help ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Saturday, November 04, 2006 1:31:53 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 4/11/2006 Kaspersky Anti-Virus database records: 224771 ——————————————————————————- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ D:\ E:\ Scan Statistics: Total number of scanned objects: 87240 Number of viruses found: 3 Number of infected objects: 3 / 0 Number of suspicious objects: 2 Duration of the scan process: 00:50:01 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip/somaticCAB.exe Suspicious: Password-protected-EXE skipped C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip ZIP: suspicious - 1 skipped C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\history.dat Object is locked skipped C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\parent.lock Object is locked skipped C:\Documents and Settings\Jason\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Jason\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Jason\Local Settings\History\History.IE5\MSHist012006110420061105\index.dat Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Temp\off93D.tmp Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Temp\~DF5E74.tmp Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Temp\~DFBF3.tmp Object is locked skipped C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Jason\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Jason\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Jason\UserData\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped C:\Program Files\Throw by Throw\2005 playoff limitations.xls Object is locked skipped C:\RECYCLER\S-1-5-21-557728558-3751186989-1254056498-1008\Dc5.exe Infected: Trojan-Downloader.Win32.Small.amb skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\A0092144.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\EventCache\{4EAF183B-10F5-49F8-8027-6F209BAB6CDC}.bin Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\config\default Object is locked skipped C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\config\software Object is locked skipped C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\SYSTEM32\config\system Object is locked skipped C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
STEP 1.
======
AboutBuster
  • Download AboutBuster.
    AboutBuster
  • Unzip AboutBuster in an own folder such as C:\AboutBuster.
  • Start AboutBuster.exe. Click OK, Update, Check For Update and download the updates if present.
  • Start Aboutbuster and let it scan. When the scan is done and you choose exit, it will automatically create a log in the same folder where aboutbuster is in.
  • Please post the results.
STEP 2.
======
Go to the Control Panel,=>Add Remove or Programs locate and click Quicktime to highlight it and then click it to Remove

STEP 3.
======
Hijackthis Delete on Reboot tool
  • Start Hijackthis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the button labeled Delete a file on reboot…
  • A new window will open asking you to select the file that you would like to delete on reboot. Navigate to the file (if it still exists after the Add/Remove Quicktime step):
    C:\Program Files\QuickTime\qttask.exe
    Click on it once, and then click on the Open button.
  • You will now be asked if you would like to reboot your computer to delete the file. Click on the Yes button if you would like to reboot now.
Empty your recycle bin. Please run Kapersky again.

Please post the Aboutbuster log, and the Kapersky log, and another hijackthis log.
As you requested, here are the 3 logs……….

AboutBuster 6.05
Scan started on [11/5/2006] at [2:25:49 AM]
————————————————————-
Internet Explorer Instances Terminated!
HomeSearch Service stopped if present
————————————————————-
No Ads Found!
————————————————————-
No Files Found!
————————————————————-
Scan was COMPLETED SUCCESSFULLY at 2:26:47 AM


———————

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Sunday, November 05, 2006 3:21:42 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 5/11/2006
Kaspersky Anti-Virus database records: 224837
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\

Scan Statistics:
Total number of scanned objects: 87318
Number of viruses found: 3
Number of infected objects: 3 / 0
Number of suspicious objects: 2
Duration of the scan process: 00:46:58

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip/somaticCAB.exe Suspicious: Password-protected-EXE skipped
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SearchCentrix7.zip ZIP: suspicious - 1 skipped
C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\cert8.db Object is locked skipped
C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\history.dat Object is locked skipped
C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\key3.db Object is locked skipped
C:\Documents and Settings\Jason\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\parent.lock Object is locked skipped
C:\Documents and Settings\Jason\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Application Data\Mozilla\Firefox\Profiles\5ruo29vy.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\History\History.IE5\MSHist012006110520061106\index.dat Object is locked skipped
C:\Documents and Settings\Jason\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jason\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jason\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Jason\UserData\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\A0092144.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\A0092280.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\A0092284.exe Infected: Trojan-Downloader.Win32.Small.amb skipped
C:\System Volume Information\_restore{1536FC13-E172-47EA-ABF3-40B443C9C015}\RP1375\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{EFA3F29F-7697-4931-B04E-70EB6D19C3E0}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\SYSTEM32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default Object is locked skipped
C:\WINDOWS\SYSTEM32\config\default.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software Object is locked skipped
C:\WINDOWS\SYSTEM32\config\software.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system Object is locked skipped
C:\WINDOWS\SYSTEM32\config\system.LOG Object is locked skipped
C:\WINDOWS\SYSTEM32\h323log.txt Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\SYSTEM32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


—————————

Logfile of HijackThis v1.99.1
Scan saved at 3:22:04 AM, on 11/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Jason\Desktop\stuff to clean the computer\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jason\Application Data\Mozilla\Profiles\default\7uuk8bnm.slt\prefs.js)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Bowmans Poker Room - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BOWMAN~1\client.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 4.0.0.320 - http://63.102.226.240:8000/Java/cfs40320.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131419283531
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned35.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: Adobe Acrobat 5.0 - {10EE3672-C265-2E74-4E09-E178B429A706} - c:\program files\adobe\acrobat 5.0\reader\ufomfn32.dll (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


THANKS
Hello jayfan41,

Please set your system to show all files; please see here if you're unsure how to do this.

STEP 1.
======
Stop and Disable Service
  • Go to Start > Run and type in Services.msc then cllick OK
  • Click the Extended tab.
  • Scroll down until you find Service: .NET Framework Service (.NET Connection Service)
  • Click once on the service to highlight it.
  • Click Stop
  • Right-Click on the service.
  • Click on 'Properties'
  • Select the 'General' tab
  • Click the Arrow-down tab on the right-hand side on the 'Start-up Type' box
  • From the drop-down menu, click on ‘Disabled'
  • Click the 'Apply' tab, then click 'OK'
The service is now stopped and disabled.

Scan with HijackThis. Place a check against each of the following:
O21 - SSODL: Adobe Acrobat 5.0 - {10EE3672-C265-2E74-4E09-E178B429A706} - c:\program files\adobe\acrobat 5.0\reader\ufomfn32.dll (file missing)
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Close all windows or browsers except for Hijackthis. Click on Fix Checked when finished and exit HijackThis.

Post (reply) with a fresh HijackThis log and we will take another look.
Hi there
I followed your instructions, EXCEPT when I was disabling Service: .NET Framework Service (.NET Connection Service), one of the instructions was "Click Stop"……….I didn't see a "Stop" option……only "start", which I did NOT click on……I followed the rest of the instructions after this - hopefully this doesn't make a difference.

Also, when I ran Hijack This as you requested, I did NOT see the following as you had asked me to check and fix:

O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)

Below is an updated Hijack This Log

thanks again

Logfile of HijackThis v1.99.1
Scan saved at 11:32:05 AM, on 11/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Jason\Desktop\stuff to clean the computer\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.com/
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Jason\Application Data\Mozilla\Profiles\default\7uuk8bnm.slt\prefs.js)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll (file missing)
O9 - Extra button: Bowmans Poker Room - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\BOWMAN~1\client.exe
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.bestbuy.msn.com
O16 - DPF: ChatSpace Full Java Client 4.0.0.320 - http://63.102.226.240:8000/Java/cfs40320.cab
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1131419283531
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {8E28B3A9-FE83-45D1-B657-D5426B81A121} (CustomerCtrl Class) - http://cs6b.instantservice.com/jars/customerxsigned35.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9FC5238F-12C4-454F-B1B5-74599A21DE47} (Webshots Photo Uploader) - http://community.webshots.com/html/WSPhotoUploader.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: intu-res - {9CE7D474-16F9-4889-9BB9-53E2008EAE8A} - C:\Program Files\Common Files\Intuit\intu-res.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs:
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
My main concern is that you had the following file on your system.
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINDOWS\svchost.exe (file missing)
http://www.castlecops.com/o23list-626.html
I would recommend that you change all your passwords. If you are concerned about possible Identity Theft, please read the following:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

I do not see a firewall application. Although Windows XP has a firewall, do not rely on the Windows XP firewall. Please read the tutorial listed below and install a firewall.

Your logs appear to be clean now. The next step will clear the infected _restore files detected by Kapersky.

STEP 1.-
======
System Restore for Windows XP
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
  • Turn off System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.
Reboot.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check *Turn off System Restore*.
  • Click Apply, and then click OK.

STEP 2.
======
DON’T BECOME OVERCONFIDENT WITH ANTIVIRUS APPLICATIONS INSTALLED!!!

http://forum.malwareremoval.com/viewtopic….39eba6ea0b5e8ee

Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.

"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."


Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly.
    For a tutorial on Firewalls and a listing of some available ones see the link below:
    Understanding and Using Firewalls

  • Test your Firewall - Please test your firewall and make sure it is working properly.
    Test Firewall

  • Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
    A tutorial on installing & using this product can be found here:
    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
    A tutorial on installing & using this product can be found here:
    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
    A tutorial on installing & using this product can be found here:
    Using SpywareBlaster to protect your computer from Spyware and Malware


  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

  • More info on how to prevent malware you can also find here (By Tony Klein)
Follow this list and your potential for being infected again will reduce dramatically.

Thank you for allowing me to assist you.

Susan
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI