This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved]Adware.agent.bn

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Somehow this (Adware.Agent.BN) has slipped through the net on my work laptop (Sophos protection)

I have installed and run:
AdwareAlert
Spyware Doctor
Zone Alarm

They keep removing bugs but everytime I reboot it is still there!
It has installed 3 icons on the desktop:
"Error Cleaner"
"Privacy Protector"
"Spyware & Protection"
These are shortcuts to websites
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...
http://virusprotectionproonline.com/shandler.php?s...

Anyway I keep getting a pop up saying Windows has detected a virus and then it opens IE and trys to goto various sites (Url is referencing something to do with a virus - "safewebnavigate"

I am also getting a red circle with a white cross on the toolbar which flashes and "virus warnings pop up from it also"

Does anyone know the best way to remove this, it doesnt seem to be doing anything else.

It is really starting to get annoying now especially as these spyware remover programmes are still not getting rid completely of it.

I have attached the log from HijackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:04:21, on 13/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Equant\Dialer\EACSvrMngr.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Free Download Manager\fdm.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Equant\Dialer\dialer.exe
C:\Program Files\Equant\Dialer\EACSys.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavMain.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\WINDOWS\System32\uWDF.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SavProgress.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/newintranet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet/newintranet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Capgemini UK plc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = websense:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet;intratest;dtxwebserver;tolorl;cbtweb;tbu;deliver.iweb.ey.com;sharepoint
cgey.com;peoplecube.capgemini.co.uk;https://www.topaz.genieinternet.com;192.168.26.248;knew.capgemini.com;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: MSVPS System - {47C54F02-1B28-45F1-AE46-B5CDFB6E7926} - C:\WINDOWS\duocore.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\TOOLBAND.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoamingClient] "C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe"
O4 - HKLM\..\Run: [SP2DelFiles] c:\progra~1\novadigm\radntfyc localhost radrexxw SP2del.rex
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\RunOnce: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe" /1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [AdwareAlert] C:\Program Files\AdwareAlert\AdwareAlert.exe -boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - S-1-5-18 Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'SYSTEM')
O4 - .DEFAULT Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - .DEFAULT User Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: InterCheck Monitor.LNK = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet/newintranet
O15 - Trusted Zone: http://cgfind.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk
O15 - Trusted Zone: http://spade.capgemini.com
O15 - Trusted Zone: http://spadecrm.capgemini.com
O15 - Trusted Zone: http://spadereporting.capgemini.com
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr
O15 - Trusted Zone: http://www.conecx-test.co.uk
O15 - Trusted Zone: http://chs.web.ey.com
O15 - Trusted Zone: http://deliver.iweb.ey.com
O15 - Trusted Zone: http://home.iweb.ey.com
O15 - Trusted Zone: http://my.infotriever.com
O15 - Trusted Zone: http://*.intranet
O15 - Trusted Zone: http://www.metalink.oracle.com
O15 - Trusted Zone: http://chat.scholars.com
O15 - Trusted Zone: http://capgemini.skillport.com
O15 - Trusted Zone: http://www.skillsoft.com
O15 - Trusted Zone: http://ccp.smartforce.com
O15 - Trusted Zone: http://content.smartforce.com
O15 - Trusted Zone: http://courseware.smartforce.com
O15 - Trusted Zone: http://dhtml.smartforce.com
O15 - Trusted Zone: http://discussions.smartforce.com
O15 - Trusted Zone: http://ghost.smartforce.com
O15 - Trusted Zone: http://jwolf.smartforce.com
O15 - Trusted Zone: http://my.smartforce.com
O15 - Trusted Zone: http://pet.smartforce.com
O15 - Trusted Zone: http://real01.smartforce.com
O15 - Trusted Zone: http://reports.smartforce.com
O15 - Trusted Zone: http://seminar01.smartforce.com
O15 - Trusted Zone: http://skl.smartforce.com
O15 - Trusted Zone: http://wms01.smartforce.com
O15 - Trusted Zone: http://www.smartforce.com
O15 - Trusted Zone: http://www.virtuallythere.com
O15 - Trusted Zone: http://cgfind.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://spade.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadecrm.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadereporting.capgemini.com (HKLM)
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr (HKLM)
O15 - Trusted Zone: http://www.conecx-test.co.uk (HKLM)
O15 - Trusted Zone: http://chs.web.ey.com (HKLM)
O15 - Trusted Zone: http://deliver.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://home.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://my.infotriever.com (HKLM)
O15 - Trusted Zone: http://*.intranet (HKLM)
O15 - Trusted Zone: http://www.metalink.oracle.com (HKLM)
O15 - Trusted Zone: http://chat.scholars.com (HKLM)
O15 - Trusted Zone: http://capgemini.skillport.com (HKLM)
O15 - Trusted Zone: http://www.skillsoft.com (HKLM)
O15 - Trusted Zone: http://ccp.smartforce.com (HKLM)
O15 - Trusted Zone: http://content.smartforce.com (HKLM)
O15 - Trusted Zone: http://courseware.smartforce.com (HKLM)
O15 - Trusted Zone: http://dhtml.smartforce.com (HKLM)
O15 - Trusted Zone: http://discussions.smartforce.com (HKLM)
O15 - Trusted Zone: http://ghost.smartforce.com (HKLM)
O15 - Trusted Zone: http://jwolf.smartforce.com (HKLM)
O15 - Trusted Zone: http://my.smartforce.com (HKLM)
O15 - Trusted Zone: http://pet.smartforce.com (HKLM)
O15 - Trusted Zone: http://real01.smartforce.com (HKLM)
O15 - Trusted Zone: http://reports.smartforce.com (HKLM)
O15 - Trusted Zone: http://seminar01.smartforce.com (HKLM)
O15 - Trusted Zone: http://skl.smartforce.com (HKLM)
O15 - Trusted Zone: http://wms01.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.virtuallythere.com (HKLM)
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - https://www.wanadoo.co.uk/time/anytimereg_d…rs/sd0101_5.exe
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ws000202:18001/qcbin/Spider80.ocx
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {761CFA89-FE48-42E7-B4E4-638ED17E72A2} (dtxProject.dtx) - file://C:\5.11\dtx.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ve.ukie.capgemini.com/dana-cached/s…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\Software\..\Telephony: DomainName = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{32F98DFB-90FB-4A97-A730-76ED4787BE32}: NameServer = 10.16.16.28 10.16.112.38
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: Domain = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer = 10.16.31.17,10.16.23.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O21 - SSODL: wmpenv - {DB7B6586-84D5-4539-A02E-001F7490F8A3} - C:\WINDOWS\wmpenv.dll
O21 - SSODL: wmpconf - {91943DCA-B71B-4E7D-AFF5-798F3A0F9D12} - C:\WINDOWS\wmpconf.dll
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: (Equant Access Companion) Services Manager (EACSvrMngr) - Unknown owner - C:\Program Files\Equant\Dialer\EACSvrMngr.exe
O23 - Service: (Equant Access Companion) Devices and Services Monitoring (EACSys) - Unknown owner - C:\Program Files\Equant\Dialer\EACSys.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: ipUnplugged Roaming Client Service (w2kMCService) - ipUnplugged - C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
O23 - Service: XFSrvcNT - Hewlett-Packard - C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 17004 bytes
Hi trig and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
Hi Dave, many thanks for helping! Here is the log from Smitfraudfix: SmitFraudFix v2.211 Scan done at 9:31:24.85, 14/08/2007 Run from C:\Documents and Settings\awain\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe C:\WINDOWS\system32\svchost.exe C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe C:\Program Files\Altiris\AClient\AClient.exe C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Equant\Dialer\EACSvrMngr.exe C:\Program Files\Novadigm\radexecd.exe C:\Program Files\Novadigm\radsched.exe C:\Program Files\Novadigm\Radstgms.exe C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Spyware Doctor\svcntaux.exe C:\Program Files\Spyware Doctor\swdsvc.exe C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe C:\Program Files\Sophos\Remote Management System\RouterNT.exe C:\WINDOWS\System32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\TalkTalk\bin\sprtcmd.exe C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe C:\Program Files\Spyware Doctor\SDTrayApp.exe C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE C:\Program Files\Microsoft Office Communicator\Communicator.exe C:\Program Files\AdwareAlert\AdwareAlert.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe C:\WINDOWS\System32\uWDF.exe C:\WINDOWS\system32\cmd.exe C:\WINDOWS\System32\wbem\wmiprvse.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS C:\WINDOWS\duocore.dll FOUND ! C:\WINDOWS\privacy_danger FOUND ! C:\WINDOWS\wmpconf.dll FOUND ! C:\WINDOWS\wmpenv.dll FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\awain »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\awain\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\awain\MYDOCU~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="file:///C:\\WINDOWS\\privacy_danger\\index.htm" "SubscribedURL"="" "FriendlyName"="Privacy Protection" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: HP WLAN 802.11b/g W400 - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: HP WLAN 802.11b/g W400 - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: HP WLAN 802.11b/g W400 - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: IPU Mobile IP Virtual Adapter - Packet Scheduler Miniport DNS Server Search Order: 10.16.31.17 DNS Server Search Order: 10.16.23.138 HKLM\SYSTEM\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CCS\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CS1\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{1BC2451D-645F-4113-AA7E-1E0CD35FEACC}: DhcpNameServer=192.168.2.1 HKLM\SYSTEM\CS2\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CS2\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End Thanks Andy
Hi Andy,

Nice job so far.

Running the Clean
Download AVG Anti-Spyware from Here and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Delete".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.

______________________________

Warning: running option #2 on a non infected computer will remove your Desktop background.


Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.

[external image: Posted Image]

The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware, and run a full scan.
  • IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • AVG will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it as a text file on your Desktop (make sure to remember where you saved that file, this is important).
Close AVG Anti-Spyware and Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing
Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________

Please post:
1.c:\rapport.txt
2.AVG Anti-Spyware log
3.A new HijackThis log

Your may need several replies to post the requested logs, otherwise they might get cut off.
Things are looking better… here are the 3 log files: Rapport file: SmitFraudFix v2.211 Scan done at 13:59:20.99, 14/08/2007 Run from C:\Documents and Settings\awain\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\duocore.dll Deleted C:\WINDOWS\privacy_danger\ Deleted C:\WINDOWS\wmpconf.dll Deleted C:\WINDOWS\wmpenv.dll Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: IPU Mobile IP Virtual Adapter - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: IPU Mobile IP Virtual Adapter - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: IPU Mobile IP Virtual Adapter - Packet Scheduler Miniport DNS Server Search Order: 10.16.14.2 DNS Server Search Order: 10.16.22.2 Description: IPU Mobile IP Virtual Adapter - Packet Scheduler Miniport DNS Server Search Order: 10.16.31.17 DNS Server Search Order: 10.16.23.138 HKLM\SYSTEM\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CCS\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CCS\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CS1\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{1BC2451D-645F-4113-AA7E-1E0CD35FEACC}: DhcpNameServer=192.168.2.1 HKLM\SYSTEM\CS2\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer=10.16.31.17,10.16.23.138 HKLM\SYSTEM\CS2\Services\Tcpip\..\{76140011-70A5-41AD-894E-453DA12F2CEE}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{BA3A7C5E-37F3-487B-B3B7-F8B9444FA76B}: DhcpNameServer=10.16.14.2 10.16.22.2 HKLM\SYSTEM\CS2\Services\Tcpip\..\{FD09805E-2702-4673-BF84-AA82C968F034}: DhcpNameServer=10.16.14.2 10.16.22.2 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
AVG report ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 14:57:47 14/08/2007 + Scan result: C:\Program Files\Google\Toolbar for Firefox\google-toolbar.xpi/components/googletoolbar.dll -> Adware.Beginto : Cleaned. C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbar.dll -> Adware.Beginto : Cleaned. :mozilla.10:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.13:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.71:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.73:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.74:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.8:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.9:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.180:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbureau : Cleaned. :mozilla.187:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Adbureau : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34.qit -> TrackingCookie.Adbureau : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\13-08-2007-08-39-10.qit -> TrackingCookie.Adbureau : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34\1.qit -> TrackingCookie.Atdmt : Cleaned. :mozilla.75:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.5:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.6:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.7:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34\3.qit -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34\4.qit -> TrackingCookie.Questionmarket : Cleaned. :mozilla.119:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.120:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.121:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.122:C:\Documents and Settings\awain\Application Data\Mozilla\Firefox\Profiles\cdvmfc90.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34\2.qit -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\awain\Application Data\AdwareAlert\Quarantine\12-08-2007-21-18-34\6.qit -> TrackingCookie.Serving-sys : Cleaned. ::Report end
Latest Hijackthis report:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:59:57, on 14/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Equant\Dialer\EACSvrMngr.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Downloads\HiJackThis.exe
C:\Program Files\Equant\Dialer\dialer.exe
C:\Program Files\Equant\Dialer\EACSys.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet/newintranet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Capgemini UK plc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = websense:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet;intratest;dtxwebserver;tolorl;cbtweb;tbu;deliver.iweb.ey.com;sharepoint
cgey.com;peoplecube.capgemini.co.uk;https://www.topaz.genieinternet.com;192.168.26.248;knew.capgemini.com;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\TOOLBAND.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoamingClient] "C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe"
O4 - HKLM\..\Run: [SP2DelFiles] c:\progra~1\novadigm\radntfyc localhost radrexxw SP2del.rex
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe" /1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: InterCheck Monitor.LNK = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet/newintranet
O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - https://www.wanadoo.co.uk/time/anytimereg_d…rs/sd0101_5.exe
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ws000202:18001/qcbin/Spider80.ocx
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {761CFA89-FE48-42E7-B4E4-638ED17E72A2} (dtxProject.dtx) - file://C:\5.11\dtx.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ve.ukie.capgemini.com/dana-cached/s…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\Software\..\Telephony: DomainName = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: Domain = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer = 10.16.31.17,10.16.23.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: (Equant Access Companion) Services Manager (EACSvrMngr) - Unknown owner - C:\Program Files\Equant\Dialer\EACSvrMngr.exe
O23 - Service: (Equant Access Companion) Devices and Services Monitoring (EACSys) - Unknown owner - C:\Program Files\Equant\Dialer\EACSys.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: ipUnplugged Roaming Client Service (w2kMCService) - ipUnplugged - C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
O23 - Service: XFSrvcNT - Hewlett-Packard - C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe

–
End of file - 11681 bytes
Hi Dave, The PC is feeling better the pop ups have stopped and it is running faster. As mentioned I have posted the 3 logs as requested, if you can let me know if anything else needs doing, Cheers Andy
Hi Andy,

Yes, looks good. Nice job! Just some cleanup with HJT and you need to update Java. Let's also run a Kaspersky scan to make sure nothing is hiding.


Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O16 - DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - https://www.wanadoo.co.uk/time/anytimereg_d…rs/sd0101_5.exe

Then close all windows except this one and press Fix checked.


——————————————————————————–


Your Java Runtime Environment is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u2.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u2, The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation, Multi-language and save it to your desktop.
  • Close any programs you may have running - especially any web browsers.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u2-windowsi586.exe to install the newest version.
—————————————————————————-


Using Internet Explorer, click on Kaspersky Online Scanner * You will be prompted to install an ActiveX component from Kaspersky, Click 'Yes'.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save as Text' button:
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.
Kaspersky log: ——————————————————————————- KASPERSKY ONLINE SCANNER REPORT Wednesday, August 15, 2007 4:59:32 PM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.93.0 Kaspersky Anti-Virus database last update: 15/08/2007 Kaspersky Anti-Virus database records: 381444 ——————————————————————————- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 72773 Number of viruses found: 2 Number of infected objects: 6 Number of suspicious objects: 0 Duration of the scan process: 02:05:57 Infected Object Name / Virus Name / Last Action C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\Config\interchk.chk Object is locked skipped C:\Documents and Settings\All Users\Application Data\Sophos\Sophos Anti-Virus\logs\SAV.txt Object is locked skipped C:\Documents and Settings\awain\Application Data\Microsoft\Outlook\Outlook~1.srs Object is locked skipped C:\Documents and Settings\awain\Cookies\index.dat Object is locked skipped C:\Documents and Settings\awain\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\awain\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\awain\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\Documents and Settings\awain\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Documents and Settings\awain\Local Settings\Application Data\ipUnplugged\Roaming Client\log.dat Object is locked skipped C:\Documents and Settings\awain\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\awain\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\awain\Local Settings\Application Data\SupportSoft\talktalk\AWAIN\state\logs\sprtcmd.log Object is locked skipped C:\Documents and Settings\awain\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\awain\Local Settings\History\History.IE5\MSHist012007081520070816\index.dat Object is locked skipped C:\Documents and Settings\awain\Local Settings\Temp\ExchangePerflog_8484fa31126b4c87cfcccd43.dat Object is locked skipped C:\Documents and Settings\awain\Local Settings\Temp\Free Download Manager\tic59.tmp Object is locked skipped C:\Documents and Settings\awain\Local Settings\Temp\Free Download Manager\tic5A.tmp Object is locked skipped C:\Documents and Settings\awain\Local Settings\Temp\Free Download Manager\tic6E.tmp Object is locked skipped C:\Documents and Settings\awain\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\awain\My Documents\Cap Back up email\Personal Folders(1).pst Object is locked skipped C:\Documents and Settings\awain\My Documents\My Videos\Car\Coupe\other\netpumper-1.50-setup-NP_0001.exe/data0079 Infected: Trojan.Win32.Obfuscated.en skipped C:\Documents and Settings\awain\My Documents\My Videos\Car\Coupe\other\netpumper-1.50-setup-NP_0001.exe Inno: infected - 1 skipped C:\Documents and Settings\awain\My Documents\outlook.ost Object is locked skipped C:\Documents and Settings\awain\ntuser.dat Object is locked skipped C:\Documents and Settings\awain\NTUSER.DAT.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Program Files\ISS\issSensors\DesktopProtection\blackice-service.log Object is locked skipped C:\Program Files\ISS\issSensors\DesktopProtection\log007.enc Object is locked skipped C:\Program Files\Novadigm\AXF\Bin\Service\Log\20070815_for_LTPXPAWAIN.Csv Object is locked skipped C:\Program Files\Novadigm\Log\radexecd.log Object is locked skipped C:\Program Files\Novadigm\Log\radsched.log Object is locked skipped C:\Program Files\Novadigm\Log\radstgms.log Object is locked skipped C:\Program Files\Novadigm\Usage Manager\Log\Usage_Log_For_20070815.Csv Object is locked skipped C:\Program Files\Novadigm\Usage Manager\Monitor.USDBase Object is locked skipped C:\Program Files\Sophos\Remote Management System\Agent\Logs\Agent-20070815-090051.log Object is locked skipped C:\Program Files\Sophos\Remote Management System\Router\Logs\Router-20070815-090053.log Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\catsrvut.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatex.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\clbcatq.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\colbact.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comadmin.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comrepl.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comsvcs.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\comuid.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\es.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\migregdb.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcprx.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtctm.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\msdtcuiu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxclu.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\mtxoci.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\ole32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcrt4.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\rpcss.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB828741$\txflog.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\dao360.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\expsrv.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexch40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msexcl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjet40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjetoledb40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjint40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjter40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msjtes40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msltus40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mspbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd2x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrd3x40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msrepl40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mstext40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswdat10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\mswstr10.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\msxbde40.dll Object is locked skipped C:\WINDOWS\$NtUninstallKB837001$\vbajet32.dll Object is locked skipped C:\WINDOWS\$_hpcst$.hpc Object is locked skipped C:\WINDOWS\CSC\000001 Object is locked skipped C:\WINDOWS\Debug\Netlogon.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\ModemLog_Agere Systems AC'97 Modem.txt Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\default Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\software Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\system Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\Temp\Perflib_Perfdata_8a4.dat Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:01:20, on 15/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe
C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Novadigm\AXF\Bin\XFStatus.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Microsoft Office Communicator\Communicator.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Sophos\AutoUpdate\ALMon.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackice.exe
C:\Program Files\Altiris\AClient\AClient.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\Equant\Dialer\EACSvrMngr.exe
C:\Program Files\Novadigm\radexecd.exe
C:\Program Files\Novadigm\radsched.exe
C:\Program Files\Novadigm\Radstgms.exe
C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Sophos\Remote Management System\RouterNT.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Equant\Dialer\dialer.exe
C:\Program Files\Equant\Dialer\EACSys.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://intranet/newintranet
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://intranet/newintranet
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Capgemini UK plc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = websense:8080
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = intranet;intratest;dtxwebserver;tolorl;cbtweb;tbu;deliver.iweb.ey.com;sharepoint
cgey.com;peoplecube.capgemini.co.uk;https://www.topaz.genieinternet.com;192.168.26.248;knew.capgemini.com;
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: NOW!Imaging - {9AA2F14F-E956-44B8-8694-A5B615CDF341} - C:\Program Files\ONSPEED\components\NOWImaging.dll (file missing)
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdmcks.dll
O3 - Toolbar: ONSPEED - {8B79EE88-E62D-4AA8-B530-CC357BA112B7} - C:\Program Files\ONSPEED\TOOLBAND.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe"
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RoamingClient] "C:\Program Files\ipUnplugged\Roaming Client\w2kConfig.exe"
O4 - HKLM\..\Run: [SP2DelFiles] c:\progra~1\novadigm\radntfyc localhost radrexxw SP2del.rex
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [!AXF XFRunOne.Exe] "C:\Program Files\Novadigm\AXF\Bin\XFRunOne.Exe" /1
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - .DEFAULT User Startup: Shortcut to 1stlog0n.lnk = C:\WINDOWS\1stlog0n.bat (User 'Default user')
O4 - Startup: VPN Dialer (OnStartup).lnk = ?
O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Program Files\Sophos\AutoUpdate\ALMon.exe
O4 - Global Startup: InterCheck Monitor.LNK = ?
O4 - Global Startup: RealSecure® Desktop Protector.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\inetrepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://intranet/newintranet
O15 - Trusted Zone: http://cgfind.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk
O15 - Trusted Zone: http://spade.capgemini.com
O15 - Trusted Zone: http://spadecrm.capgemini.com
O15 - Trusted Zone: http://spadereporting.capgemini.com
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr
O15 - Trusted Zone: http://www.conecx-test.co.uk
O15 - Trusted Zone: http://chs.web.ey.com
O15 - Trusted Zone: http://deliver.iweb.ey.com
O15 - Trusted Zone: http://home.iweb.ey.com
O15 - Trusted Zone: http://my.infotriever.com
O15 - Trusted Zone: http://*.intranet
O15 - Trusted Zone: http://www.metalink.oracle.com
O15 - Trusted Zone: http://chat.scholars.com
O15 - Trusted Zone: http://capgemini.skillport.com
O15 - Trusted Zone: http://www.skillsoft.com
O15 - Trusted Zone: http://ccp.smartforce.com
O15 - Trusted Zone: http://content.smartforce.com
O15 - Trusted Zone: http://courseware.smartforce.com
O15 - Trusted Zone: http://dhtml.smartforce.com
O15 - Trusted Zone: http://discussions.smartforce.com
O15 - Trusted Zone: http://ghost.smartforce.com
O15 - Trusted Zone: http://jwolf.smartforce.com
O15 - Trusted Zone: http://my.smartforce.com
O15 - Trusted Zone: http://pet.smartforce.com
O15 - Trusted Zone: http://real01.smartforce.com
O15 - Trusted Zone: http://reports.smartforce.com
O15 - Trusted Zone: http://seminar01.smartforce.com
O15 - Trusted Zone: http://skl.smartforce.com
O15 - Trusted Zone: http://wms01.smartforce.com
O15 - Trusted Zone: http://www.smartforce.com
O15 - Trusted Zone: http://www.virtuallythere.com
O15 - Trusted Zone: http://cgfind.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmisprodas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas1.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas2.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://cgmissuppas3.capgemini.co.uk (HKLM)
O15 - Trusted Zone: http://spade.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadecrm.capgemini.com (HKLM)
O15 - Trusted Zone: http://spadereporting.capgemini.com (HKLM)
O15 - Trusted Zone: http://mygalaxyclassic.capgemini.fr (HKLM)
O15 - Trusted Zone: http://www.conecx-test.co.uk (HKLM)
O15 - Trusted Zone: http://chs.web.ey.com (HKLM)
O15 - Trusted Zone: http://deliver.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://home.iweb.ey.com (HKLM)
O15 - Trusted Zone: http://my.infotriever.com (HKLM)
O15 - Trusted Zone: http://*.intranet (HKLM)
O15 - Trusted Zone: http://www.metalink.oracle.com (HKLM)
O15 - Trusted Zone: http://chat.scholars.com (HKLM)
O15 - Trusted Zone: http://capgemini.skillport.com (HKLM)
O15 - Trusted Zone: http://www.skillsoft.com (HKLM)
O15 - Trusted Zone: http://ccp.smartforce.com (HKLM)
O15 - Trusted Zone: http://content.smartforce.com (HKLM)
O15 - Trusted Zone: http://courseware.smartforce.com (HKLM)
O15 - Trusted Zone: http://dhtml.smartforce.com (HKLM)
O15 - Trusted Zone: http://discussions.smartforce.com (HKLM)
O15 - Trusted Zone: http://ghost.smartforce.com (HKLM)
O15 - Trusted Zone: http://jwolf.smartforce.com (HKLM)
O15 - Trusted Zone: http://my.smartforce.com (HKLM)
O15 - Trusted Zone: http://pet.smartforce.com (HKLM)
O15 - Trusted Zone: http://real01.smartforce.com (HKLM)
O15 - Trusted Zone: http://reports.smartforce.com (HKLM)
O15 - Trusted Zone: http://seminar01.smartforce.com (HKLM)
O15 - Trusted Zone: http://skl.smartforce.com (HKLM)
O15 - Trusted Zone: http://wms01.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.smartforce.com (HKLM)
O15 - Trusted Zone: http://www.virtuallythere.com (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {205E7068-6D03-4566-AD06-A146B592FBA5} (Loader Class v2) - http://ws000202:18001/qcbin/Spider80.ocx
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {761CFA89-FE48-42E7-B4E4-638ED17E72A2} (dtxProject.dtx) - file://C:\5.11\dtx.CAB
O16 - DPF: {E5F5D008-DD2C-4D32-977D-1A0ADF03058B} (JuniperSetupSP1 Control) - https://ve.ukie.capgemini.com/dana-cached/s…perSetupSP1.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\Software\..\Telephony: DomainName = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{32F98DFB-90FB-4A97-A730-76ED4787BE32}: NameServer = 10.16.16.28 10.16.112.38
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: Domain = uki.capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{56BA3966-3EB7-4004-B60A-5EF5FBD92C6F}: NameServer = 10.16.31.17,10.16.23.138
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = uki.capgemini.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = uki.capgemini.com,capgemini.co.uk,capgemini.com
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\Program Files\Altiris\AClient\AClient.exe
O23 - Service: AdwareAlert Scanning Engine (AdwareAlertSrv) - Unknown owner - C:\Program Files\AdwareAlert\AdwareAlertSrv.srv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BlackICE - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\blackd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: (Equant Access Companion) Services Manager (EACSvrMngr) - Unknown owner - C:\Program Files\Equant\Dialer\EACSvrMngr.exe
O23 - Service: (Equant Access Companion) Devices and Services Monitoring (EACSys) - Unknown owner - C:\Program Files\Equant\Dialer\EACSys.exe
O23 - Service: Radia Notify Daemon (radexecd) - Hewlett-Packard - C:\Program Files\Novadigm\radexecd.exe
O23 - Service: Radia Scheduler Daemon (radsched) - Hewlett-Packard - C:\Program Files\Novadigm\radsched.exe
O23 - Service: Radia MSI Redirector (Radstgms) - Hewlett-Packard - C:\Program Files\Novadigm\Radstgms.exe
O23 - Service: RapApp - Internet Security Systems, Inc. - C:\Program Files\ISS\issSensors\DesktopProtection\RapApp.exe
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Plc - C:\Program Files\Sophos\Sophos Anti-Virus\SavService.exe
O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
O23 - Service: Sophos Agent - Sophos Plc - C:\Program Files\Sophos\Remote Management System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Plc - C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Plc - C:\Program Files\Sophos\Remote Management System\RouterNT.exe
O23 - Service: ipUnplugged Roaming Client Service (w2kMCService) - ipUnplugged - C:\Program Files\ipUnplugged\Roaming Client\w2kMCService.exe
O23 - Service: XFSrvcNT - Hewlett-Packard - C:\Program Files\Novadigm\AXF\Bin\XFSrvcNT.Exe

–
End of file - 15872 bytes
Well Kaspersky did not find much. Just this:

C:\Documents and Settings\awain\My Documents\My Videos\Car\Coupe\other\netpumper-1.50-setup-NP_0001.exe

Are you aware of what that .exe file is? If not I would go ahead and delete it.

All the items are back in your trusted zone. I am assuming you want those to be there and know what they are? Let me know.

Let me know how it's running at this point.
Hi, Its running like it used to (to best of my knowledge) Net pumper was a download manager I downloaded but did not use. Deleted it anyway. Most of the stuff in the trusted zone is work related so is fine there. This forum is a life saver! Many thanks for your help it is much appreciated! Thanks Andy
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)1. Turn off System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
2. Restart your computer.

3. Turn ON System Restore.On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check Turn off System Restore.
Click Apply, and then click OK.
System Restore will now be active again.

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
You should also have a good firewall. Here are 2 free ones available for personal use:and a good antivirus (these are also free for personal use):It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
  • Microsoft Windows Update
monthly. And to keep your system clean run these free malware scannersweekly, and be aware of what emails you open and websites you visit.

To learn more about how to protect yourself while on the internet read this article by Tony Klein: So how did I get infected in the first place?

Regards,
Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI