Sorry man, its just for one thing, this is difficult doing this on-line, second, this whole virus thing has just frustrated the lviing crap outa me, and third, I've NEVER been in my registry before all of this...so I am a bit nervous about what all of this is doing to my computer. One thing I'd like to say is that all the pop-ups have stopped (for now). The first hting I pasted below is that Ver3.txt that has those entries that you asked me to add to it:
logogdi.exe
ipv9x.exe
hostnameip.exe
unlodctl.exe
spnping.exe
sharenet.exe
scardsvrhr.exe
rsvph.exe
rdpclips.exe
rasaoutu.exe
qappsrvc32.exe
pentxpl.exe
openconf.exe
nlsfuncs.exe
hrlink.dll
nasll.dll
elswap.dll
dx9vbc.dll
dnsaquota.dll
dnsauth.dll
taskopen.exe
iecust.dll
iecust.exe
setvers.exe
ifcfg.exe
snnpapi.exe
snnpapi.dll
hlp32.exe
Microsoft.hta
chmredir.chm
winuptd.exe
servises.exe
tasknngr.exe
rpcnt4.dll
tksvr99.exe
w32sxp.exe
wncust.exe
tlntadmnx.exe
vwipxspnt.exe
winmsdc.exe
usrshutd.exe
tcpsvcss.exe
ms_update.exe
wmplayer.exe
amax.exe
CustIE32.dll
deski.exe
doul.exe
etile.exe
[censored]sex.exe
iesp1.dll
ipvcx6.exe
mspax.dll
nbtrstat.exe
netupd32.exe
od.exe
protect32.dll
rdspclips.exe
rexece32.exe
sethcd.exe
smbdins.exe
sprestrst.exe
tsmsetup.exe
upncont.exe
wmplayer.exe
wowdbe.exe
ywde.exe
iesp2.dll
sp2chek.exe
connmie.exe
dxconf.exe
iecustme.exe
iecustom32.dll
mxbkup.exe
truettf.exe
update.exe
sfcman32.dll
qwsxp.dll
winwiz32.exe
sp2chk.exe
sprmover.exe
msmkd.dll
sysobj.exe
wosys32.dll
woinst.exe
hdmoo.dll
hdyue.dll
OK..I have downloaded the RootKitReveal and its log is next:
C:\$AttrDef 11/1/2003 2:05 PM 2.50 KB Hidden from Windows API.
C:\$BadClus 11/1/2003 2:05 PM 0 bytes Hidden from Windows API.
C:\$BadClus:$Bad 11/1/2003 2:05 PM 37.27 GB Hidden from Windows API.
C:\$Bitmap 11/1/2003 2:05 PM 1.16 MB Hidden from Windows API.
C:\$Boot 11/1/2003 2:05 PM 8.00 KB Hidden from Windows API.
C:\$Extend 11/1/2003 2:05 PM 0 bytes Hidden from Windows API.
C:\$Extend\$ObjId 11/1/2003 2:06 PM 0 bytes Hidden from Windows API.
C:\$Extend\$Quota 11/1/2003 2:06 PM 0 bytes Hidden from Windows API.
C:\$Extend\$Reparse 11/1/2003 2:06 PM 0 bytes Hidden from Windows API.
C:\$LogFile 11/1/2003 2:05 PM 64.00 MB Hidden from Windows API.
C:\$MFT 11/1/2003 2:05 PM 48.28 MB Hidden from Windows API.
C:\$MFTMirr 11/1/2003 2:05 PM 4.00 KB Hidden from Windows API.
C:\$Secure 11/1/2003 2:05 PM 0 bytes Hidden from Windows API.
C:\$UpCase 11/1/2003 2:05 PM 128.00 KB Hidden from Windows API.
C:\$Volume 11/1/2003 2:05 PM 0 bytes Hidden from Windows API.
Next. When you wanted me to look for those files..you didn't specify to physically go into my System32 file to look for them. I copy and pasted each one into my start>>find and it looked in the System 32 folder and found 2 of that whole list. Lately, when I physically go into System 32, it doesn't list all of the files that appear on the EZ Antivirus' list for System 32, so I don't know what thats all about. I will go back to your post and physically look for those particular files again and delete them.
Regarding my Contol Panel....I guess you didn't realize that my entire Windows XP os was set up to be like classic windows when I very first got this computer...I hate the XP styling and did that first thing. But seriously, when I went into the network yesterday, the folder was empty...this morning, I just this second went into it and now I have:Local Area Connection under the heading "LAN or High Speed Internet" and two icons: New Connecton Wizard and Network Setup Wizard under the Wizard heading...will have to refer back to your previous post to see what you wanted done there again...the Obtain DNS server address automatically IS checked and in the advanced, under the DNS tab, the "Append primary and connection specific DNS suffixes" is checked as well as its sub category "Append parent suffixes of the primary DNS suffix"
Ok, you also wanted a fresh HJT log, here it is:
Logfile of HijackThis v1.99.1
Scan saved at 7:52:24 AM, on 3/7/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2
(6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\VetMsgNT.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.emachines.comR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.emachines.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
N2 - Netscape 6: user_pref("browser.search.defaultengine", engine://C%3A%5CProgram%20Files%5CNetscape%5
CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\home\Application Data\Mozilla\Profiles\default\tt64smx3.slt\prefs.js)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [VetTray] C:\PROGRA~1\CA\ETRUST~1\ETRUST~1\VetTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBKEYBOARD] C:\Program Files\MultiMedia Keyboard\MultiMedia Keyboard\1.1\KbdAp32A.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Browser MOUSE\mouse32a.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: TREND MICRO HouseCall -
{2B5EA4F8-620A-4A8B-B003-4C8C5EBEA826} -
http://uk.trendmicro-europe.com/enterprise/products/housecall_pre.php (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {7ED7005B-4AF6-4CFF-9AE0-F243C4B8260F} (HouseCallButton.setup) -
http://de.trendmicro-europe.com/file_downloads/
common/housecall/HouseCallButton.CAB
O16 - DPF: {928626A3-6B98-11CF-90B4-00AA00A4011F} (SurroundVideoCtrl Object) -
http://autos.msn.com/components/ocx/survid/MSSurVid.cab
O16 - DPF: {BB47CA33-8B4D-11D0-9511-00C04FD9152D} (ExteriorSurroundObject) -
http://autos.msn.com/components/ocx/exterior/Outside.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Email Removed AttachmentsControl) -
http://by9fd.bay9.Email Removed.msn.com/activex/HMA
tchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\WINDOWS\System32\VetMsgNT.exe
I went into System32 folder and looked for the files you told me to look for :
C:\WINDOWS\system32\date.dat
C:\WINDOWS\system32\menu.txt
C:\WINDOWS\system32\mslcy.dll
C:\WINDOWS\system32\sysobj.exe
C:\WINDOWS\system32\sprmover.exe
C:\WINDOWS\system32\connmie.exe
C:\WINDOWS\system32\ctbasxt.exe
C:\WINDOWS\system32\dxconf.exe
C:\WINDOWS\system32\hdmoo.dll
C:\WINDOWS\system32\sprmover.exe
C:\WINDOWS\system32\wosys32.dll
C:\WINDOWS\system32\woinst.exe
The only ones I found in there were the first 2: date.dat and menu.txt and i deleted them both.
Is there a way of emptying ALL the tem/temp internet files/history from all users at once? I don't have any secondary users set up on this computer...but 've got folders that say Administrator, all users, default user, home, local service, network service, AND owner. Takes 4ever to go into al of these and try to delete everything...some don't even have a Local Settings folder. And the "local Service" user won't let me delte anything at all. HEY: is "index.dat" an important file...its always in my cookies folder and it shows up in all these other fodlers and refuses to be delted...says that windows is using it. Just wondering.
Just to let you know. I work third shift. I won't get a chance to check for your post until after 6pm tonight (monday march 7) Hope what I sent in this post helps you to help me....and i don't mind working in the registry..jsut nervous about it...I want to do whatever it takes to get my computer to a point where I can set a restore point....OH BTW... what about that virus that hides in the System Volume Info file?

? I had that once and system restore became something that I don't even use anymore...took me forever to figure out how to get it out of htat folder, and now, my computer refuses to allow me access to the System Volume Information folder at all. Any ideas on that??? HAve a good one...and thanks for being patient with me.

http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/unsure.gif\' class=\'bbc_emoticon\' alt=\':unsure:\' />