This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help Please - Trojan.Vundo & Downloader

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Chaps,

some help would be appreciated. I had Norton AV tell me it had cleared up Trojan.Vundo but it kept reappearing. Norton also told me it was blocking Downloader, but my IE7 keeps starting and navigating to sites on its own.

I've run Vundofix.exe several times and after it cleared two instances, it doesn't find any infection anymore, but Norton still reacts. IE7 still stalls/spawns pages on its own.

My hijackthis.log is attached below, please can you help me to make my machine stable again.

Thanks,

Ken.


Logfile of HijackThis v1.99.1
Scan saved at 21:12:06, on 20/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {03CCB64E-FD9F-43D8-863B-CBB0EF65C7F5} - C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\HCDCHXSW\3077ahntdksr[1].dll (file missing)
O2 - BHO: (no name) - {0C7B4747-3198-469D-B67C-EA0CC4F59DC9} - C:\WINDOWS\system32\cbXQiJab.dll
O2 - BHO: (no name) - {203BA02A-401F-4141-AE79-721170410423} - C:\WINDOWS\system32\btttwsio.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: (no name) - {6AC2CB03-F72F-4A14-9F30-15D015F35D03} - C:\WINDOWS\system32\yayyYSkH.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\efcASjhH.dll (file missing)
O2 - BHO: {8a18dd71-665f-e3fb-b134-94b053fd60df} - {fd06df35-0b49-431b-bf3e-f56617dd81a8} - C:\WINDOWS\system32\yazcwn.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [1c3c66c1] rundll32.exe "C:\WINDOWS\system32\eidhxhbc.dll",b
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [BM1f0f555d] Rundll32.exe "C:\WINDOWS\system32\whxigcht.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
Hello

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.



Please download Runscanner to your desktop and run it.
  • When the first page comes up select Beginner Mode
  • On the next page select Save a binary .Run file (Recommended) then click Start full scan at the top.
  • At this time Runscanner.exe may request access to the Internet through your firewall please allow it to do so, it will then run for two or three minutes.
  • On completion it will ask for a location to save the file and a name. It will do this for both the .run file and the log file
  • Call the .run file "Select a name" and save it to your desktop. You will see the .run file on your desktop. Upload that file here. If the forum doesn't let you upload it then please zip the .run file by right clicking and selecting send to Zip file

Then upload that as an attachment in your next post (you may have to zip the .run file to upload it here).
Thanks for helping me.

Ok, I have run Vundofix a couple of times over the last couple of days. Its log is of all the runs todate is below, as is the hijackthis log I've just run.

The attached zip file contains the .log and the .run files created by Runscanner.

Thanks in advance for your continued support.

Ken.

Vundofix.txt

VundoFix V7.0.6

Scan started at 22:44:59 18/07/2008

Listing files found while scanning….

C:\Windows\system32\btttwsio.dll
C:\Windows\system32\efcASjhH.dll

Beginning removal…

Attempting to delete C:\Windows\system32\btttwsio.dll
C:\Windows\system32\btttwsio.dll Has been deleted!

Attempting to delete C:\Windows\system32\efcASjhH.dll
C:\Windows\system32\efcASjhH.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Performing Repairs to the registry.
Done!

VundoFix V7.0.6

Scan started at 22:59:04 18/07/2008

Listing files found while scanning….

C:\Windows\system32\efcASjhH.dll

Beginning removal…

Attempting to delete C:\Windows\system32\efcASjhH.dll
C:\Windows\system32\efcASjhH.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\Windows\system32\efcASjhH.dll
C:\Windows\system32\efcASjhH.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V7.0.6

Scan started at 23:31:30 18/07/2008

Listing files found while scanning….

C:\Windows\system32\efcASjhH.dll

Beginning removal…

Attempting to delete C:\Windows\system32\efcASjhH.dll
C:\Windows\system32\efcASjhH.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal…

Attempting to delete C:\Windows\system32\efcASjhH.dll
C:\Windows\system32\efcASjhH.dll Could not be deleted.

Performing Repairs to the registry.
Done!

VundoFix V7.0.6

Scan started at 00:01:42 19/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 00:33:51 19/07/2008

Listing files found while scanning….


VundoFix V7.0.6

Scan started at 16:20:28 19/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 19:13:06 20/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 20:52:49 20/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 12:33:38 21/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 15:48:57 21/07/2008

Listing files found while scanning….

No infected files were found.


VundoFix V7.0.6

Scan started at 18:43:16 21/07/2008

Listing files found while scanning….

No infected files were found.

Hijackthis.log

Logfile of HijackThis v1.99.1
Scan saved at 19:29:38, on 21/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {03CCB64E-FD9F-43D8-863B-CBB0EF65C7F5} - C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\HCDCHXSW\3077ahntdksr[1].dll (file missing)
O2 - BHO: (no name) - {203BA02A-401F-4141-AE79-721170410423} - C:\WINDOWS\system32\btttwsio.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: (no name) - {6AC2CB03-F72F-4A14-9F30-15D015F35D03} - C:\WINDOWS\system32\yayyYSkH.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: {c224cae6-3f9e-3efa-5384-28596e4cd8b8} - {8b8dc4e6-9582-4835-afe3-e9f36eac422c} - C:\WINDOWS\system32\swpudu.dll
O2 - BHO: (no name) - {BE7E4CE1-8CBA-44A6-956F-462A667D3286} - C:\WINDOWS\system32\efcASjhH.dll (file missing)
O2 - BHO: (no name) - {F306C074-8286-4CE3-9304-59B5BA57C52E} - C:\WINDOWS\system32\cbXQiJab.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [1c3c66c1] rundll32.exe "C:\WINDOWS\system32\qlaeiaun.dll",b
O4 - HKLM\..\Run: [BM1f0f555d] Rundll32.exe "C:\WINDOWS\system32\mkaywmmw.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
Hello

Download the attachment at the end of this post (this will be your runscanner file fixed by me)

  • Unzip it to your desktop then double click the runscanner icon this will run the program.
  • You will notice several entries in red and in blue.
  • Click the button at the top called Fix selected items
  • Accept the warning(s) and repeat until they are all gone.
  • Reboot your PC



Please download Deckard's System Scanner (DSS) and save it to your Desktop.
  • Close all other windows before proceeding.
  • Double-click on dss.exe and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
  • When it has finished, dss will open two Notepads main.txt and extra.txt – please copy (CTRL+A and then CTRL+C) and paste (CTRL+V) the contents of main.txt and extra.txt in your next reply.

Attachments:

Ok .. I've run the runscanner file you fixed for me, and after rebooting, I have run the Deckards System Scanner.

As requested, below are the contents of the main.txt and extra.txt files.

Thanks again for your ongoing help :-D

Main.txt

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-22 02:09:05
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

System Restore is disabled; attempting to re-enable…success.


– Last 1 Restore Point(s) –
1: 2008-07-22 01:09:08 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



– HijackThis (run as ks.exe) ————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 02:10:33, on 22/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Documents and Settings\ks\Desktop\dss.exe
C:\HIJACK~1\ks.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {A15863C4-1DF6-43D5-8DC6-656DEA1DA397} - C:\WINDOWS\system32\cbXQiJab.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo;! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [BM1f0f555d] Rundll32.exe "C:\WINDOWS\system32\mkaywmmw.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe


– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 AsIO - c:\windows\system32\drivers\asio.sys
R2 ASInsHelp - c:\windows\system32\drivers\asinshelp32.sys

S3 EraserUtilDrv10741 - c:\program files\common files\symantec shared\eengine\eraserutildrv10741.sys (file missing)


– Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ——————–

S3 NBService - c:\program files\nero\nero 7\nero backitup\nbservice.exe


– Device Manager: Disabled —————————————————-

No disabled devices found.


– Scheduled Tasks ————————————————————-

2008-07-22 02:00:43 616 –a—— C:\WINDOWS\Tasks\Norton Internet Security - Run Full System Scan - ks.job


– Files created between 2008-06-22 and 2008-07-22 —————————–

2008-07-21 12:41:39 77312 –a—— C:\WINDOWS\system32\qlaeiaun.dll
2008-07-21 12:38:40 102912 –a—— C:\WINDOWS\system32\swpudu.dll
2008-07-21 12:38:39 102912 –a—— C:\WINDOWS\system32\lelwbvjh.dll
2008-07-21 12:35:38 91648 –a—— C:\WINDOWS\system32\mkaywmmw.dll
2008-07-20 19:13:06 0 d——– C:\VundoFix Backups
2008-07-20 19:03:34 0 d——– C:\Hijackthis
2008-07-20 02:51:54 102912 –a—— C:\WINDOWS\system32\yazcwn.dll
2008-07-20 02:51:53 102912 –a—— C:\WINDOWS\system32\mqlchxnp.dll
2008-07-20 02:49:37 91711 –a—— C:\WINDOWS\system32\akrqfato.dll
2008-07-20 02:49:31 91136 –a—— C:\WINDOWS\system32\whxigcht.dll
2008-07-18 22:34:51 0 d——– C:\WINDOWS\CSC
2008-07-18 22:04:38 0 d——– C:\WINDOWS\pss
2008-07-18 18:14:55 102912 –a—— C:\WINDOWS\system32\nuibye.dll
2008-07-18 18:14:54 102912 –a—— C:\WINDOWS\system32\cmvqfnmy.dll
2008-07-18 18:06:54 91648 –a—— C:\WINDOWS\system32\cdaevtkw.dll
2008-07-18 18:03:53 604878 –ahs—- C:\WINDOWS\system32\baJiQXbc.ini2
2008-07-18 18:03:51 319488 –a—— C:\WINDOWS\system32\cbXQiJab.dll
2008-07-17 18:10:32 0 d——– C:\Documents and Settings\ks\Application Data\Macromedia
2008-07-17 16:24:39 91711 –a—— C:\WINDOWS\system32\vequrrry.dll
2008-07-17 15:12:13 91711 –a—— C:\WINDOWS\system32\iowfuprk.dll
2008-07-15 22:45:43 91711 –a—— C:\WINDOWS\system32\dvcgfaxa.dll
2008-07-15 22:38:59 91711 –a—— C:\WINDOWS\system32\jclahvlh.dll
2008-07-15 18:19:48 90236 –a—— C:\WINDOWS\system32\jjiecyaw.dll
2008-07-15 18:18:41 593130 –ahs—- C:\WINDOWS\system32\dgPYHkkj.ini2
2008-07-14 22:44:15 88791 –a—— C:\WINDOWS\system32\liqaqrnb.dll
2008-07-14 22:41:15 593659 –ahs—- C:\WINDOWS\system32\yyJkRXyb.ini2
2008-07-14 09:33:30 91711 –a—— C:\WINDOWS\system32\kuktdnci.dll
2008-07-11 16:37:38 0 d——– C:\spoolerlogs
2008-07-10 22:23:02 91711 –a—— C:\WINDOWS\system32\yxkclaao.dll
2008-06-28 09:12:34 103424 –a—— C:\WINDOWS\system32\xyokxndw.dll
2008-06-28 09:12:34 103424 –a—— C:\WINDOWS\system32\bsduuj.dll
2008-06-28 09:09:34 90624 –a—— C:\WINDOWS\system32\hepnscwc.dll
2008-06-27 21:07:55 0 d——– C:\Documents and Settings\ks\Application Data\dvdcss
2008-06-27 21:06:18 45056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    C:\WINDOWS\system32\qlaeiaun.dll
    C:\WINDOWS\system32\swpudu.dll
    C:\WINDOWS\system32\lelwbvjh.dll
    C:\WINDOWS\system32\mkaywmmw.dll
    C:\VundoFix Backups
    C:\WINDOWS\system32\yazcwn.dll
    C:\WINDOWS\system32\mqlchxnp.dll
    C:\WINDOWS\system32\akrqfato.dll
    C:\WINDOWS\system32\whxigcht.dll
    C:\WINDOWS\system32\nuibye.dll
    C:\WINDOWS\system32\cmvqfnmy.dll
    C:\WINDOWS\system32\cdaevtkw.dll
    C:\WINDOWS\system32\baJiQXbc.ini2
    C:\WINDOWS\system32\cbXQiJab.dll
    C:\WINDOWS\system32\vequrrry.dll
    C:\WINDOWS\system32\iowfuprk.dll
    C:\WINDOWS\system32\dvcgfaxa.dll
    C:\WINDOWS\system32\jclahvlh.dll
    C:\WINDOWS\system32\jjiecyaw.dll
    C:\WINDOWS\system32\dgPYHkkj.ini2
    C:\WINDOWS\system32\liqaqrnb.dll
    C:\WINDOWS\system32\yyJkRXyb.ini2
    C:\WINDOWS\system32\kuktdnci.dll
    C:\WINDOWS\system32\yxkclaao.dll
    C:\WINDOWS\system32\xyokxndw.dll
    C:\WINDOWS\system32\bsduuj.dll
    C:\WINDOWS\system32\hepnscwc.dll
    C:\WINDOWS\system32\HkSYyyay.ini2
    C:\WINDOWS\system32\yayyYSkH.dll
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Also post a new DSS log
Rorschach112,

thanks for your continued support.

I have completed the steps you posted and used OTMoveIt2 as directed. Below I have pasted the resultant log file that was produced, and then I have posted main.txt file which was created by DSS. Please note DSS didn't seem to create an extra.txt file this time round.

Regards,

Ken.


07222008_202738.log

Explorer killed successfully
DllUnregisterServer procedure not found in C:\WINDOWS\system32\qlaeiaun.dll
C:\WINDOWS\system32\qlaeiaun.dll NOT unregistered.
C:\WINDOWS\system32\qlaeiaun.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\swpudu.dll
C:\WINDOWS\system32\swpudu.dll NOT unregistered.
C:\WINDOWS\system32\swpudu.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\lelwbvjh.dll
C:\WINDOWS\system32\lelwbvjh.dll NOT unregistered.
C:\WINDOWS\system32\lelwbvjh.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mkaywmmw.dll
C:\WINDOWS\system32\mkaywmmw.dll NOT unregistered.
C:\WINDOWS\system32\mkaywmmw.dll moved successfully.
C:\VundoFix Backups moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yazcwn.dll
C:\WINDOWS\system32\yazcwn.dll NOT unregistered.
C:\WINDOWS\system32\yazcwn.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mqlchxnp.dll
C:\WINDOWS\system32\mqlchxnp.dll NOT unregistered.
C:\WINDOWS\system32\mqlchxnp.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\akrqfato.dll
C:\WINDOWS\system32\akrqfato.dll NOT unregistered.
C:\WINDOWS\system32\akrqfato.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\whxigcht.dll
C:\WINDOWS\system32\whxigcht.dll NOT unregistered.
C:\WINDOWS\system32\whxigcht.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\nuibye.dll
C:\WINDOWS\system32\nuibye.dll NOT unregistered.
C:\WINDOWS\system32\nuibye.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cmvqfnmy.dll
C:\WINDOWS\system32\cmvqfnmy.dll NOT unregistered.
C:\WINDOWS\system32\cmvqfnmy.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cdaevtkw.dll
C:\WINDOWS\system32\cdaevtkw.dll NOT unregistered.
C:\WINDOWS\system32\cdaevtkw.dll moved successfully.
C:\WINDOWS\system32\baJiQXbc.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cbXQiJab.dll
C:\WINDOWS\system32\cbXQiJab.dll NOT unregistered.
C:\WINDOWS\system32\cbXQiJab.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\vequrrry.dll
C:\WINDOWS\system32\vequrrry.dll NOT unregistered.
C:\WINDOWS\system32\vequrrry.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\iowfuprk.dll
C:\WINDOWS\system32\iowfuprk.dll NOT unregistered.
C:\WINDOWS\system32\iowfuprk.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\dvcgfaxa.dll
C:\WINDOWS\system32\dvcgfaxa.dll NOT unregistered.
C:\WINDOWS\system32\dvcgfaxa.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\jclahvlh.dll
C:\WINDOWS\system32\jclahvlh.dll NOT unregistered.
C:\WINDOWS\system32\jclahvlh.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\jjiecyaw.dll
C:\WINDOWS\system32\jjiecyaw.dll NOT unregistered.
C:\WINDOWS\system32\jjiecyaw.dll moved successfully.
C:\WINDOWS\system32\dgPYHkkj.ini2 moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\liqaqrnb.dll
C:\WINDOWS\system32\liqaqrnb.dll NOT unregistered.
C:\WINDOWS\system32\liqaqrnb.dll moved successfully.
C:\WINDOWS\system32\yyJkRXyb.ini2 moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\kuktdnci.dll
C:\WINDOWS\system32\kuktdnci.dll NOT unregistered.
C:\WINDOWS\system32\kuktdnci.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\yxkclaao.dll
C:\WINDOWS\system32\yxkclaao.dll NOT unregistered.
C:\WINDOWS\system32\yxkclaao.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\xyokxndw.dll
C:\WINDOWS\system32\xyokxndw.dll NOT unregistered.
C:\WINDOWS\system32\xyokxndw.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\bsduuj.dll
C:\WINDOWS\system32\bsduuj.dll NOT unregistered.
C:\WINDOWS\system32\bsduuj.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\hepnscwc.dll
C:\WINDOWS\system32\hepnscwc.dll NOT unregistered.
C:\WINDOWS\system32\hepnscwc.dll moved successfully.
C:\WINDOWS\system32\HkSYyyay.ini2 moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yayyYSkH.dll
C:\WINDOWS\system32\yayyYSkH.dll NOT unregistered.
C:\WINDOWS\system32\yayyYSkH.dll moved successfully.
< purity >
< EmptyTemp >
File delete failed. C:\WINDOWS\temp\JET6E5A.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_97c.dat scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07222008_202738

Files moved on Reboot…
File C:\WINDOWS\temp\JET6E5A.tmp not found!
C:\WINDOWS\temp\Perflib_Perfdata_97c.dat moved successfully.


main.txt

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-22 20:35:25
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as ks.exe) ————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 20:35:28, on 22/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\ks\Desktop\dss.exe
C:\HIJACK~1\ks.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: (no name) - {5E0B5081-96DF-4651-AE0D-DD69272961E1} - C:\WINDOWS\system32\cbXQiJab.dll (file missing)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKLM\..\Run: [BM1f0f555d] Rundll32.exe "C:\WINDOWS\system32\mkaywmmw.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe


– Files created between 2008-06-22 and 2008-07-22 —————————–

2008-07-20 19:03:34 0 d——– C:\Hijackthis
2008-07-18 22:34:51 0 d——– C:\WINDOWS\CSC
2008-07-18 22:04:38 0 d——– C:\WINDOWS\pss
2008-07-17 18:10:32 0 d——– C:\Documents and Settings\ks\Application Data\Macromedia
2008-07-11 16:37:38 0 d——– C:\spoolerlogs
2008-06-27 21:07:55 0 d——– C:\Documents and Settings\ks\Application Data\dvdcss
2008-06-27 21:06:18 45056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
Hello

1. Please re-open HiJackThis and choose do a system scan only. Check the boxes next to ONLY the entries listed below(if present):

O2 - BHO: (no name) - {5E0B5081-96DF-4651-AE0D-DD69272961E1} - C:\WINDOWS\system32\cbXQiJab.dll (file missing)
O4 - HKLM\..\Run: [BM1f0f555d] Rundll32.exe "C:\WINDOWS\system32\mkaywmmw.dll",s


2. Now close all windows other than HiJackThis, including browsers, so that nothing other than HijackThis is open, then click Fix Checked. A box will pop up asking you if you wish to fix the selected items. Please choose YES. Once it has fixed them, please exit/close HijackThis.



Please do an online scan with Kaspersky WebScanner

Make sure you are using Internet Explorer for this. Click on Kaspersky Online Scanner and click Accept

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.


Also post a new DSS log
Rorschach112,

just finished doing the kaspersky scan, and it seemed to find lots of things … eeekkkkkkk and I've dilligently been using NIS2008 !!!

The log files you asked for are attached below, the scan file from kaspersky and the main.txt from DSS.

Thanks for your continued support .. what next …

Ken.

kaspersky scan report 24th Jul.txt

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Thursday, July 24, 2008 1:19:21 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 23/07/2008
Kaspersky Anti-Virus database records: 998522
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics:
Total number of scanned objects: 199204
Number of viruses found: 19
Number of infected objects: 226
Number of suspicious objects: 0
Duration of the scan process: 03:55:09

Infected Object Name / Virus Name / Last Action
C:\Deckard\System Scanner\20080722203126\backup\DOCUME~1\ks\LOCALS~1\Temp\NERO14688\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\volatile.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\{EBB14FB2-A6B3-4A1B-A431-FB9F41354146}.DAT Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2008-07-23_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{632172C8-637D-44AD-8551-E658EE21679A}.ldb Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\Shl_{632172C8-637D-44AD-8551-E658EE21679A}.sds Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\DC5B8A06.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\F0024121.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\ks\Application Data\Symantec\NPMDataStore\CIMStore.xml Object is locked skipped
C:\Documents and Settings\ks\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\ks\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\History\History.IE5\MSHist012008072320080724\index.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Temp\~DFF2EA.tmp Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Temp\~DFF305.tmp Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\KHGI95EX\kb671231[1] Infected: Trojan.Win32.Monderc.gen skipped
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\N53GDQ7Q\kb456456[1] Infected: Trojan.Win32.Monderc.gen skipped
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\PANXS8OH\kb767887[1] Infected: Trojan.Win32.Monderc.gen skipped
C:\Documents and Settings\ks\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\ks\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\NFWEVT.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{6C40C906-0B9E-4AA3-B432-8629F748FB2D}\RP1\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\S96CD3DA8.tmp Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\LogFiles\HTTPERR\httperr1.log Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\JET7D1A.tmp Object is locked skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\akrqfato.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\bsduuj.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\cbXQiJab.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\cdaevtkw.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\cmvqfnmy.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\dvcgfaxa.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\hepnscwc.dll Infected: Trojan.Win32.Monder.wj skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\iowfuprk.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\jclahvlh.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\jjiecyaw.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\kuktdnci.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\lelwbvjh.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\liqaqrnb.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\mkaywmmw.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\mqlchxnp.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\nuibye.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\qlaeiaun.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\swpudu.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\vequrrry.dll Infected: Trojan.Win32.Obfuscated.auw skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\whxigcht.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\xyokxndw.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\yayyYSkH.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\yazcwn.dll Infected: Trojan.Win32.Monderc.gen skipped
C:\_OTMoveIt\MovedFiles\07222008_202738\WINDOWS\system32\yxkclaao.dll Infected: Trojan.Win32.Obfuscated.auw skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst/Ken BT Openworld/Inbox/07 Jan 2006 12:19 from Alan Scott:VNC/vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst/Ken BT Openworld/Inbox/07 Jan 2006 12:19 from Alan Scott:VNC/vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst/Ken BT Openworld/Inbox/07 Jan 2006 12:19 from Alan Scott:VNC/vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0006 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst/Ken BT Openworld/Inbox/07 Jan 2006 12:19 from Alan Scott:VNC/vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst/Ken BT Openworld/Inbox/07 Jan 2006 12:19 from Alan Scott:VNC/vnc-4.0-x86_win32.zip Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Ken Mail\Ken BT Openworld.pst MailMSMaill: infected - 5 skipped
F:\From P4 Desk\Ken Mail\Ken1.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from [removed]:1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken1.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken1.pst MailMSMaill: infected - 2 skipped
F:\From P4 Desk\Ken Mail\Ken2.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from ken.2.scott@bt.com1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken2.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken2.pst MailMSMaill: infected - 2 skipped
F:\From P4 Desk\Ken Mail\Ken3.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from [removed]:1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken3.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\From P4 Desk\Ken Mail\Ken3.pst MailMSMaill: infected - 2 skipped
F:\From P4 Desk\Temp\vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0002 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Temp\vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0003 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Temp\vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe/data0006 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Temp\vnc-4.0-x86_win32.zip/vnc-4.0-x86_win32.exe Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped
F:\From P4 Desk\Temp\vnc-4.0-x86_win32.zip ZIP: infected - 4 skipped
F:\Local Disk (D)\My Shared Folder\DivX Player Alpha 2.0 - Pro 5.0.2.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
F:\Local Disk (D)\My Shared Folder\DivX Player Alpha 2.0 - Pro 5.0.2.exe Vise: infected - 1 skipped
F:\Local Disk (I)\Data\Genie\aTemp\Temp\Temp\limtemp.zip/limtempud5thmar04.pst/Personal Folders/Sent Items/25 Feb 2002 22:39 from [removed]:Re: Fwd: Sex a/Alternative Horoscopes.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Data\Genie\aTemp\Temp\Temp\limtemp.zip/limtempud5thmar04.pst Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Data\Genie\aTemp\Temp\Temp\limtemp.zip ZIP: infected - 2 skipped
F:\Local Disk (I)\Data\Genie\aTemp\Temp\Temp\limtempud5thmar04.pst/Personal Folders/Sent Items/25 Feb 2002 22:39 from [removed]:Re: Fwd: Sex a/Alternative Horoscopes.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Data\Genie\aTemp\Temp\Temp\limtempud5thmar04.pst MailMSMaill: infected - 1 skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/28 Jan 2000 16:27 from Williams,C,Carol,KSGD3 C:Whereabouts/JP Team Whereabouts comp.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/11 Jun 1999 17:48 from Wilson,S,KSGD3 WILSONS4 M:FW: Re run of T/OrgPresDay.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/16 Feb 2000 17:52 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:APR's/APR00kc.DOC Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/16 Feb 2000 17:52 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:APR's/APR00rf.DOC Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/13 Jul 1999 13:39 from Manosperti,M,KSFC MANOSPM M:P1 3rd party /3RDPTY01.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/28 Jan 2000 16:39 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:EIN's/EIN.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/20 Jul 1999 20:13 from Larman,Ian,IG,KSOG34 LARMANI X:RE: Citiba/Citi_FTE.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/22 Jul 1999 10:57 from Haigh, Paul:Discount Scheme/AddVantage Review.doc Infected: Virus.MSWord.Class.d skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/03 Aug 1999 15:42 from Manosperti,M,Mark,KSFC X:FW: Overseas P4/FM'OSEAS.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/03 Aug 1999 18:01 from Manosperti,M,Mark,KSFC X:FW: 3rd Party - /3RDPTY04.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/04 Aug 1999 14:34 from Manosperti,M,Mark,KSFC X:CVNS/Citibank CVNS Double bill P4.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/05 Aug 1999 15:04 from Manosperti,M,Mark,KSFC X:RE: Billing sale/BILL04.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/17 Aug 1999 12:54 from Pickett,Trevor,TL,KSOG33 PICKETTL X:Revis/status.doc Infected: Virus.MSWord.Story skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/18 Aug 1999 08:15 from Pickett,Trevor,TL,KSOG33 PICKETTL X:Probl/status-merged.doc Infected: Virus.MSWord.VMPC-based skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/18 Aug 1999 23:17 from Ken Scott:July's Trunk Cost1.xls/July's Trunk Cost1.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/23 Aug 1999 16:59 from Manosperti,M,Mark,KSFC X:FW: Citibank Rev/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/23 Aug 1999 16:59 from Manosperti,M,Mark,KSFC X:FW: Citibank Rev/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/22 Aug 1999 21:00 from Ken Scott:Contract Review/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/22 Aug 1999 21:00 from Ken Scott:Contract Review/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/23 Aug 1999 12:23 from Picton,JA,Julie,KSGD3 X:FW: URGENT: TOP: /ATT-Advise.doc Infected: Virus.MSWord.Story skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/24 Aug 1999 12:39 from Manosperti,M,Mark,KSFC X:RE: Citibank Rev/Citi P3 contract review.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/24 Aug 1999 12:39 from Manosperti,M,Mark,KSFC X:RE: Citibank Rev/Citi P3 contract review.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/20 Sep 1999 11:15 from Thomas,EA,Eric,KSGD3 R:Voice Helpdesk Act/Citibank Voice Helpdesk Action Points.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/22 Sep 1999 10:54 from [removed]:Re: Farnborough/newvoice.doc Infected: Virus.MSWord.VMPC-based skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/BT.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Eurocom.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Different Calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Matched calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/10 Oct 1999 21:40 from Ken Scott:Re : Operator Bonus/Operator Pay.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/10 Oct 1999 21:35 from Ken Scott:Re : Operator Bonus/Operator Pay.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/10 Feb 2000 12:51 from CITIBANK H:Minutes of Service Review Meet/Meeting Minutes 8 February 2000.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/07 Feb 2000 17:10 from Butchers,Dave,DJ,KSOG34 BUTCHEDJ X:lUCENT/LUCENT COSTS TO KSCOTT.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/22 Jan 2000 14:45 from Cottrell,K,Ken,KSGD3 COTTREK R:AFN Delive/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/02 Dec 1999 17:55 from Gardner,A,Tony,KSGD3 GARDENT R:FW: C-View/Content30-11-99.doc Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/08 Dec 1999 18:31 from Gardner,A,Tony,KSGD3 GARDENT R:FW: C-View/Content30-11-99.doc Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/04 Jan 2000 17:49 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:FW: PSG AP/APRCOM99.DOC Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/14 Jan 2000 17:34 from Thomas,EA,Eric,KSGD3 R:Oliver minutes 14./Oliver minutes 14.01.00.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/17 Jan 2000 22:50 from Cottrell,K,Ken,KSGD3 COTTREK R:FW: SSB He/SSB Helpdesk.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/18 Jan 2000 21:15 from Cottrell,K,Ken,KSGD3 COTTREK R:RE: Compen/Tandem Site EngineerV2.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/21 Jan 2000 09:15 from Cottrell,K,Ken,KSGD3 COTTREK R:Weekly Rep/011400.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/03 Feb 1999 12:03 from David Pollard:[Fwd: SSB]/02 Feb 1999 11:10 to Richard Barker; David Pollard:SSB/MtgSBB.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/24 Jan 2000 15:41 from CITIBANK H:Monthly Report/December 1999.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/25 Jan 2000 12:30 from Reeves,Chris,CG,KSOG34 REEVESC2 X:Lewisha/BTSS Report on Lewishan Power unit Failure.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/26 Jan 2000 11:25 from CITIBANK H:Monthly Report/December 1999.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/03 Feb 1999 12:54 from David Pollard:[Fwd: January -Voice Activi/02 Feb 1999 10:45 to Wayne Niles; jcoelho; Keith Skinner; David /jan99.report.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/28 Jan 2000 13:55 from Butchers,Dave,DJ,KSOG34 BUTCHEDJ X:Oliver/Citibank Early Occupation Action Points updates.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/25 Mar 1999 14:10 from Buglass, Paul, BUGLASP2:Definity/Meridian/baby test3.doc Infected: Virus.MSWord.Marker.fq2 skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/09 Apr 1999 10:43 from Kuberski, Robert:FW: Price Lists/CS Labour Rates.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/11 May 1999 13:58 from Buglass, Paul, BUGLASP2:Report /vrecd_2.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Inbox/14 May 1999 10:57 from Harrison,M,KSOG1 HARRI296 M:Citibank Y2K /Citipbx.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/21 Jan 2000 10:10 to BTL VIRUS TEAM:Suspect File/suspect.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/04 Aug 1999 10:53 to Manosperti,M,Mark,KSFC X:P4 Updated with 3/P4_Citi.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/19 Aug 1999 07:26 to Cottrell,K,Kenneth,KSGD3 X:FW: July's Trunk/July's Trunk Cost1.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 12:22 to Manosperti,M,Mark,KSFC X:Citibank Review/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 12:22 to Manosperti,M,Mark,KSFC X:Citibank Review/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 17:56 to Pell,S,Sarah,IGF22 NOBLES3 X; Wolsoncroft,D/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 17:56 to Pell,S,Sarah,IGF22 NOBLES3 X; Wolsoncroft,D/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/24 Aug 1999 11:42 to Manosperti,M,Mark,KSFC X:FW: Citibank Revie/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/24 Aug 1999 11:42 to Manosperti,M,Mark,KSFC X:FW: Citibank Revie/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/31 Aug 1999 08:22 to Picton,JA,Julie,KSGD3 X:Presentation and Ti/Citip3 99 Review Demorski.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/31 Aug 1999 08:22 to Picton,JA,Julie,KSGD3 X:Presentation and Ti/Citip3 99 Review Demorski.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/BT.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Eurocom.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Different Calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Matched calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/17 Apr 2000 16:50 to '[removed]':Con Rev/June 1999 Contract Review.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/17 Apr 2000 16:50 to '[removed]':Con Rev/June 1999 Contract Review.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/12 Apr 1999 07:25 to Hewitt,TA,BGGD32 HEWITTTA M; Reeves,CG,BGOG/CS Labour Rates.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/20 Jan 2000 18:40 to 'Julia Hicks':Alternative Horoscopes/Alternative Horoscopes.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/12 May 1999 07:04 to Reeves,CG,KSOG34 REEVESC2 M; 'ian.larman@bt/vrecd_2.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst/Personal Folders/Sent Items/17 May 1999 11:51:Monthly Report/MON0499.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK\ScottK.pst MailMSMaill: infected - 73 skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/28 Jan 2000 16:27 from Williams,C,Carol,KSGD3 C:Whereabouts/JP Team Whereabouts comp.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/11 Jun 1999 17:48 from Wilson,S,KSGD3 WILSONS4 M:FW: Re run of T/OrgPresDay.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/16 Feb 2000 17:52 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:APR's/APR00kc.DOC Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/16 Feb 2000 17:52 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:APR's/APR00rf.DOC Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/13 Jul 1999 13:39 from Manosperti,M,KSFC MANOSPM M:P1 3rd party /3RDPTY01.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/28 Jan 2000 16:39 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:EIN's/EIN.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/20 Jul 1999 20:13 from Larman,Ian,IG,KSOG34 LARMANI X:RE: Citiba/Citi_FTE.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/22 Jul 1999 10:57 from Haigh, Paul:Discount Scheme/AddVantage Review.doc Infected: Virus.MSWord.Class.d skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/03 Aug 1999 15:42 from Manosperti,M,Mark,KSFC X:FW: Overseas P4/FM'OSEAS.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/03 Aug 1999 18:01 from Manosperti,M,Mark,KSFC X:FW: 3rd Party - /3RDPTY04.XLS Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/04 Aug 1999 14:34 from Manosperti,M,Mark,KSFC X:CVNS/Citibank CVNS Double bill P4.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/05 Aug 1999 15:04 from Manosperti,M,Mark,KSFC X:RE: Billing sale/BILL04.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/17 Aug 1999 12:54 from Pickett,Trevor,TL,KSOG33 PICKETTL X:Revis/status.doc Infected: Virus.MSWord.Story skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/18 Aug 1999 08:15 from Pickett,Trevor,TL,KSOG33 PICKETTL X:Probl/status-merged.doc Infected: Virus.MSWord.VMPC-based skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/18 Aug 1999 23:17 from Ken Scott:July's Trunk Cost1.xls/July's Trunk Cost1.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/23 Aug 1999 16:59 from Manosperti,M,Mark,KSFC X:FW: Citibank Rev/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/23 Aug 1999 16:59 from Manosperti,M,Mark,KSFC X:FW: Citibank Rev/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/22 Aug 1999 21:00 from Ken Scott:Contract Review/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/22 Aug 1999 21:00 from Ken Scott:Contract Review/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/23 Aug 1999 12:23 from Picton,JA,Julie,KSGD3 X:FW: URGENT: TOP: /ATT-Advise.doc Infected: Virus.MSWord.Story skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/24 Aug 1999 12:39 from Manosperti,M,Mark,KSFC X:RE: Citibank Rev/Citi P3 contract review.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/24 Aug 1999 12:39 from Manosperti,M,Mark,KSFC X:RE: Citibank Rev/Citi P3 contract review.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/20 Sep 1999 11:15 from Thomas,EA,Eric,KSGD3 R:Voice Helpdesk Act/Citibank Voice Helpdesk Action Points.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/22 Sep 1999 10:54 from [removed]:Re: Farnborough/newvoice.doc Infected: Virus.MSWord.VMPC-based skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/BT.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Eurocom.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Different Calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip/Matched calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Oct 1999 00:22 from Ken Scott:CNIC / Eurocom Analysis/Reconcilliation.zip Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/10 Oct 1999 21:40 from Ken Scott:Re : Operator Bonus/Operator Pay.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/10 Oct 1999 21:35 from Ken Scott:Re : Operator Bonus/Operator Pay.XLS Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/10 Feb 2000 12:51 from CITIBANK H:Minutes of Service Review Meet/Meeting Minutes 8 February 2000.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/07 Feb 2000 17:10 from Butchers,Dave,DJ,KSOG34 BUTCHEDJ X:lUCENT/LUCENT COSTS TO KSCOTT.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/22 Jan 2000 14:45 from Cottrell,K,Ken,KSGD3 COTTREK R:AFN Delive/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/02 Dec 1999 17:55 from Gardner,A,Tony,KSGD3 GARDENT R:FW: C-View/Content30-11-99.doc Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/08 Dec 1999 18:31 from Gardner,A,Tony,KSGD3 GARDENT R:FW: C-View/Content30-11-99.doc Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/04 Jan 2000 17:49 from Hewitt,TA,Tim,KSGD3 HEWITTTA R:FW: PSG AP/APRCOM99.DOC Infected: Virus.MSWord.Class.ed skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/14 Jan 2000 17:34 from Thomas,EA,Eric,KSGD3 R:Oliver minutes 14./Oliver minutes 14.01.00.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/17 Jan 2000 22:50 from Cottrell,K,Ken,KSGD3 COTTREK R:FW: SSB He/SSB Helpdesk.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/18 Jan 2000 21:15 from Cottrell,K,Ken,KSGD3 COTTREK R:RE: Compen/Tandem Site EngineerV2.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/21 Jan 2000 09:15 from Cottrell,K,Ken,KSGD3 COTTREK R:Weekly Rep/011400.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/03 Feb 1999 12:03 from David Pollard:[Fwd: SSB]/02 Feb 1999 11:10 to Richard Barker; David Pollard:SSB/MtgSBB.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/24 Jan 2000 15:41 from CITIBANK H:Monthly Report/December 1999.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/25 Jan 2000 12:30 from Reeves,Chris,CG,KSOG34 REEVESC2 X:Lewisha/BTSS Report on Lewishan Power unit Failure.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/26 Jan 2000 11:25 from CITIBANK H:Monthly Report/December 1999.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/03 Feb 1999 12:54 from David Pollard:[Fwd: January -Voice Activi/02 Feb 1999 10:45 to Wayne Niles; jcoelho; Keith Skinner; David /jan99.report.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/28 Jan 2000 13:55 from Butchers,Dave,DJ,KSOG34 BUTCHEDJ X:Oliver/Citibank Early Occupation Action Points updates.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/25 Mar 1999 14:10 from Buglass, Paul, BUGLASP2:Definity/Meridian/baby test3.doc Infected: Virus.MSWord.Marker.fq2 skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/09 Apr 1999 10:43 from Kuberski, Robert:FW: Price Lists/CS Labour Rates.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/11 May 1999 13:58 from Buglass, Paul, BUGLASP2:Report /vrecd_2.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Inbox/14 May 1999 10:57 from Harrison,M,KSOG1 HARRI296 M:Citibank Y2K /Citipbx.doc Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/21 Jan 2000 10:10 to BTL VIRUS TEAM:Suspect File/suspect.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/04 Aug 1999 10:53 to Manosperti,M,Mark,KSFC X:P4 Updated with 3/P4_Citi.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/19 Aug 1999 07:26 to Cottrell,K,Kenneth,KSGD3 X:FW: July's Trunk/July's Trunk Cost1.xls Infected: Virus.MSExcel.Laroux.a skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 12:22 to Manosperti,M,Mark,KSFC X:Citibank Review/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 12:22 to Manosperti,M,Mark,KSFC X:Citibank Review/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 17:56 to Pell,S,Sarah,IGF22 NOBLES3 X; Wolsoncroft,D/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/23 Aug 1999 17:56 to Pell,S,Sarah,IGF22 NOBLES3 X; Wolsoncroft,D/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/24 Aug 1999 11:42 to Manosperti,M,Mark,KSFC X:FW: Citibank Revie/Citi P3 contract review ppt97.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/24 Aug 1999 11:42 to Manosperti,M,Mark,KSFC X:FW: Citibank Revie/Citi P3 contract review ppt97.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/31 Aug 1999 08:22 to Picton,JA,Julie,KSGD3 X:Presentation and Ti/Citip3 99 Review Demorski.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/31 Aug 1999 08:22 to Picton,JA,Julie,KSGD3 X:Presentation and Ti/Citip3 99 Review Demorski.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/BT.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Eurocom.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Different Calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip/Matched calls.xls Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/07 Oct 1999 10:16 to Lister,DM,Dave,KSVA4 X; Goodall,D,Dave,KSVA/Reconcilliation.zip Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/17 Apr 2000 16:50 to '[removed]':Con Rev/June 1999 Contract Review.ppt/Embedded Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/17 Apr 2000 16:50 to '[removed]':Con Rev/June 1999 Contract Review.ppt Infected: Virus.MSExcel.Laroux.cs skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/12 Apr 1999 07:25 to Hewitt,TA,BGGD32 HEWITTTA M; Reeves,CG,BGOG/CS Labour Rates.doc Infected: Virus.MSWord.Ethan skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/20 Jan 2000 18:40 to 'Julia Hicks':Alternative Horoscopes/Alternative Horoscopes.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/12 May 1999 07:04 to Reeves,CG,KSOG34 REEVESC2 M; 'ian.larman@bt/vrecd_2.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst/Personal Folders/Sent Items/17 May 1999 11:51:Monthly Report/MON0499.DOC Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip/ScottK.pst Infected: Virus.MSWord.FootPrint skipped
F:\Local Disk (I)\Mail\Citi Email\ScottK.zip ZIP: infected - 74 skipped
F:\Local Disk (I)\Mail\From May 2000.pst/Personal Folders/Inbox/17 Nov 2000 16:16 from Horner,AP,Tony,IVGH2 R:/ Infected: Virus.MSExcel.Jini.corrupted skipped
F:\Local Disk (I)\Mail\From May 2000.pst MailMSMaill: infected - 1 skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken\Ken2.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from ken.2.scott@bt.com1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken\Ken2.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken\Ken2.pst MailMSMaill: infected - 2 skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken3.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from [removed]:1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken3.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Local Disk (I)\Mail\Ken BT Openworld\Ken3.pst MailMSMaill: infected - 2 skipped
F:\Main - 18G Drive (F)\Mail\Ken BT Openworld Old\Ken1.pst/Personal Folders/Inbox/19 Jan 2000 19:06 from [removed]:1/EOP Plan.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Main - 18G Drive (F)\Mail\Ken BT Openworld Old\Ken1.pst/Personal Folders/Inbox/22 Jan 2000 14:46 from [removed]:AFN Delivery/Design requirements.doc Infected: Virus.MSOffice.Jerk.c skipped
F:\Main - 18G Drive (F)\Mail\Ken BT Openworld Old\Ken1.pst MailMSMaill: infected - 2 skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\_restore{042D15DE-EC04-4031-9978-119B6CB13EC4}\RP436\A0094000.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped
F:\System Volume Information\_restore{042D15DE-EC04-4031-9978-119B6CB13EC4}\RP436\A0094000.exe Vise: infected - 1 skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\DSS\MachineKeys\f35f9a0c57be0f7f06adf6874a24acb3_9f5784a0-43dd-46cf-bbfc-30cea38c6000 Object is locked skipped
H:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped
H:\Install Temp\AMV400\MSI.CAB/_6227252443C841BF9FFDFF29A9856421 Infected: not-a-virus:RiskTool.Win32.Deleter.e skipped
H:\Install Temp\AMV400\MSI.CAB CAB: infected - 1 skipped
H:\Install Temp\AMV400.rar/MSI.CAB/_6227252443C841BF9FFDFF29A9856421 Infected: not-a-virus:RiskTool.Win32.Deleter.e skipped
H:\Install Temp\AMV400.rar/MSI.CAB Infected: not-a-virus:RiskTool.Win32.Deleter.e skipped
H:\Install Temp\AMV400.rar RAR: infected - 2 skipped
H:\Install Temp\MSI.CAB/_6227252443C841BF9FFDFF29A9856421 Infected: not-a-virus:RiskTool.Win32.Deleter.e skipped
H:\Install Temp\MSI.CAB CAB: infected - 1 skipped
H:\Program Files\MP3 Player Utilities 3.5.02\DelDrv.exe Infected: not-a-virus:RiskTool.Win32.Deleter.b skipped
H:\Program Files\MP3 Player Utilities 4.00\DelDrv.exe Infected: not-a-virus:RiskTool.Win32.Deleter.e skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\callcont.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\cmdevtgprov.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\evtgprov.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\gdi32.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\h323.tsp Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\h323msp.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\helpctr.exe Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\ipnathlp.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\lsasrv.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\mf3216.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\msasn1.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\msgina.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\mst120.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\netapi32.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\nmcom.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\rtcdll.dll Object is locked skipped
H:\WINDOWS\$NtUninstallKB835732$\schannel.dll Object is locked skipped

Scan process completed.

main.txt from DSS


Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-24 01:22:20
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as ks.exe) ————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 01:22:23, on 24/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\ks\Desktop\dss.exe
C:\HIJACK~1\ks.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo;! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/ka…can_unicode.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe


– Files created between 2008-06-24 and 2008-07-24 —————————–

2008-07-22 21:43:30 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-22 21:43:29 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-07-20 19:03:34 0 d——– C:\Hijackthis
2008-07-18 22:34:51 0 d——– C:\WINDOWS\CSC
2008-07-18 22:04:38 0 d——– C:\WINDOWS\pss
2008-07-17 18:10:32 0 d——– C:\Documents and Settings\ks\Application Data\Macromedia
2008-07-11 16:37:38 0 d——– C:\spoolerlogs
2008-06-27 21:07:55 0 d——– C:\Documents and Settings\ks\Application Data\dvdcss
2008-06-27 21:06:18 45056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
Hello

Please download the OTMoveIt2 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt2.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    [kill explorer]
    H:\Install Temp\AMV400\MSI.CAB
    H:\Install Temp\MSI.CAB
    H:\Program Files\MP3 Player Utilities 3.5.02\DelDrv.exe 
    H:\Program Files\MP3 Player Utilities 4.00\DelDrv.exe
    purity 
    EmptyTemp
    [start explorer]
  • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.



Backup Your Registry with ERUNT
  • Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
  • For version with the Installer:
    Use the setup program to install ERUNT on your computer
  • For the zipped version:
    Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.

Note: to restore your registry, go to the folder and start ERDNT.exe



Now we need to fix your problems by making a .reg file. Copy the code below into a Notepad file. Name the file as fix.reg, change the "Save as Type" to "All files" and save it on the desktop.

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa]
"Authentication Packages"=hex(7):6d,00,73,00,76,00,31,00,5f,00,30,00,00,00,00,\
00


Then double click on the fix.reg file, when it prompts to merge click "Yes".




Please download Malwarebytes' Anti-Malware from Here or Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Reboot and post a new DSS log
Rorschach112,

I've completed the steps you specified. The OTMovIT2 log, MBAM log and the DSS log are attached below.

Thanks,

Ken.

OTMoveIt2 - 07252008_091542.log

Explorer killed successfully
H:\Install Temp\AMV400\MSI.CAB moved successfully.
H:\Install Temp\MSI.CAB moved successfully.
H:\Program Files\MP3 Player Utilities 3.5.02\DelDrv.exe moved successfully.
H:\Program Files\MP3 Player Utilities 4.00\DelDrv.exe moved successfully.
< purity >
< EmptyTemp >
File delete failed. C:\WINDOWS\temp\JET8C80.tmp scheduled to be deleted on reboot.
Temp folders emptied.
IE temp folders emptied.
Explorer started successfully

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07252008_091542

Files moved on Reboot…
File C:\WINDOWS\temp\JET8C80.tmp not found!


mbam-log-7-25-2008 (09-34-47).txt

Malwarebytes' Anti-Malware 1.23
Database version: 990
Windows 5.1.2600 Service Pack 2

09:34:47 25/07/2008
mbam-log-7-25-2008 (09-34-47).txt

Scan type: Quick Scan
Objects scanned: 38273
Time elapsed: 4 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 4
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 4

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{be7e4ce1-8cba-44a6-956f-462a667d3286} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\ks\Local Settings\Temporary Internet Files\Content.IE5\KHGI95EX\kb671231[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\BM1f0f555d.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM1f0f555d.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

DSS Log Main.txt

Deckard's System Scanner v20071014.68
Run by [removed] on 2008-07-25 09:38:26
Computer is in Normal Mode.
——————————————————————————–



– HijackThis (run as ks.exe) ————————————————–

Logfile of HijackThis v1.99.1
Scan saved at 09:38:31, on 25/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\ks\Desktop\dss.exe
C:\HIJACK~1\ks.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
O3 - Toolbar: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus-en/ka…can_unicode.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD40/JSCDL/jre/6u…ows-i586-jc.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe


– Files created between 2008-06-25 and 2008-07-25 —————————–

2008-07-25 09:27:53 0 d——– C:\Documents and Settings\ks\Application Data\Malwarebytes
2008-07-25 09:27:49 0 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-07-25 09:27:49 0 d——– C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-07-22 21:43:30 0 d——– C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-07-22 21:43:29 0 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-07-20 19:03:34 0 d——– C:\Hijackthis
2008-07-18 22:34:51 0 d——– C:\WINDOWS\CSC
2008-07-18 22:04:38 0 d——– C:\WINDOWS\pss
2008-07-17 18:10:32 0 d——– C:\Documents and Settings\ks\Application Data\Macromedia
2008-07-11 16:37:38 0 d——– C:\spoolerlogs
2008-06-27 21:07:55 0 d——– C:\Documents and Settings\ks\Application Data\dvdcss
2008-06-27 21:06:18 45056 –a—— C:\WINDOWS\system32\WNASPI32.DLL
Your logs are clean

You now need to update your Java and remove your older versions.

Please follow these steps to remove older version Java components.

* Click Start > Control Panel.
* Click Add/Remove Programs.
* Check any item with Java Runtime Environment (JRE) in the name.
* Click the Remove or Change/Remove button.

Download the latest version of Java Runtime Environment (JRE), and install it to your computer from
here



  • Make sure you have an Internet Connection.
  • Double-click OTMoveIt2.exe to run it.
  • Click on the CleanUp! button
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OtMoveit2 to rech the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.


Now we need to create a new System Restore point.

Click Start Menu > Run > type (or copy and paste)

%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next. Name it and click Create, when the confirmation screen shows the restore point has been created click Close.

Next goto Start Menu > Run > type

cleanmgr

Click OK, Disk Cleanup will open and start calculating the amount of space that can be freed, Once thats finished it will open the Disk Cleanup options screen, click the More Options tab then click Clean up on the system restore area and choose Yes at the confirmation window which will remove all the restore points except the one we just created.

To close Disk Cleanup and remove the Temporary Internet Files detected in the initial scan click OK then choose Yes on the confirmation window.



Below I have included a number of recommendations for how to protect your computer against malware infections.

* Keep Windows updated by regularly checking their website at :
http://windowsupdate.microsoft.com/
This will ensure your computer has always the latest security updates available installed on your computer.

* To reduce re-infection for malware in the future, I strongly recommend installing these free programs:

SpywareBlaster protects against bad ActiveX
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all
Have a look at this tutorial for IE-Spyad here

* SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program or there will be a conflict.

Make Internet Explorer more secure
  • Click Start > Run
  • Type Inetcpl.cpl & click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected & Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

* MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

* Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
Here

* Take a good look at the following suggestions for malware prevention by reading Tony Klein’s article 'How Did I Get Infected In The First Place'
Here

Thank you for your patience, and performing all of the procedures requested.
Rorschach112, a big thank you. My machine seems stable now, and I have also taken on board you last comments and added the extra spyware guard/blaster. Just a shame NIS 2008 never kept me safe in the first place :P May your good deeds come back as plenty of good karma :) Thanks again, Ken.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI