Questolo, hi...sorry so late; my laptop has been really slow and everytime I open it the hourglass stays on for a very long time and I'm unable to do anything at all at that time. Also, before I forget, I wanted to let you know that a few weeks ago, in the midst of all these problems, my roadrunner e-mail address sent out e-mails to EVERYONE in my known contacts list, most likely infected e-mails; i got a bunch returned to me, and they all said something about ebay. Anyway, here are the results of my scans, thanks:
Logfile of HijackThis v1.99.1
Scan saved at 8:29:21 PM, on 3/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\NETGEAR\MA521 Configuration Utility\wlancfg5.exe
C:\Program Files\Nikon\NkView6\NkvMon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Michelle\Desktop\hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dellnet.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://www.dellnet.com/O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Monitor] C:\PROGRA~1\LEXMAR~1\ACMonitor_X73.exe
O4 - HKLM\..\Run: [Lexmark X73 Button Manager] C:\PROGRA~1\LEXMAR~1\AcBtnMgr_X73.exe
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: WkCalRem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe
O4 - Global Startup: MA521 Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 7:01:21 PM, 3/10/2006
+ Report-Checksum: DC4E4BD3
+ Scan result:
HKU\S-1-5-21-3962561463-2826087509-1140141477-1007\Software\Microsoft\Internet Explorer\Explorer Bars\{159C2E51-9823-11D2-8DDC-D84A1B4ACD4D} -> Adware.Generic : Cleaned with backup
C:\avenger\backup.zip/avenger/PerfectNavUninstall.exe -> Downloader.Keenval.e : Cleaned with backup
C:\avenger\backup.zip/avenger/surv3.exe -> Downloader.VB.vv : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.210:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.211:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.269:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.270:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.271:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.272:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.573:C:\Documents and Settings\Michelle\Application Data\Mozilla\Firefox\Profiles\xb9fxqaz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Michelle\Desktop\backups\backup-20060205-225954-256.dll -> Adware.PurityScan : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\poe7l0sn.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\poe7l0sn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\poe7l0sn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Tony\Local Settings\Temporary Internet Files\Content.IE5\698RM5YX\!update-3395[1].0000 -> Downloader.PurityScan.bs : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP121\A0106636.exe -> Downloader.VB.dm : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP121\A0107816.dll -> Adware.PurityScan : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP123\A0117169.dll -> Trojan.Agent.eu : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP126\A0118396.exe -> Downloader.Keenval.e : Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP126\A0118401.exe -> Downloader.VB.vv : Cleaned with backup
::Report End
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\lcyyjeub
*******************
Script file located at: \??\C:\Documents and Settings\hswewmka.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\go_1.exe deleted successfully.
File C:\Program Files\Kazaa\PerfectNavUninstall.exe deleted successfully.
File C:\WINDOWS\alchem.ini deleted successfully.
File C:\WINDOWS\blocklist.reg deleted successfully.
File C:\WINDOWS\Digital Signature 20040926.htm deleted successfully.
File C:\WINDOWS\GatorUninstaller_cme.log deleted successfully.
File C:\WINDOWS\PreProcess.data deleted successfully.
File C:\WINDOWS\smdat32a.sys deleted successfully.
File C:\WINDOWS\surv3.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts.bho deleted successfully.
File C:\WINDOWS\SYSTEM32\ide21201.vxd deleted successfully.
File C:\WINDOWS\SYSTEM32\kernels64.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\O deleted successfully.
File C:\WINDOWS\SYSTEM32\O.BAT deleted successfully.
File C:\WINDOWS\SYSTEM32\shell386.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\web.exe deleted successfully.
File C:\WINDOWS\SYSTEM32\wtssvtr.exe deleted successfully.
Folder C:\Program Files\rdso deleted successfully.
Completed script processing.
*******************
Finished! Terminate.