Sorry I could not post earlier. I could not uninstall network monitor. "C:/Windows/Uninstall_nmon.vbs could not be found". I recovered the file and then unintall said it was missing a character, or something.
I deleted IE earlier. I downloaded ie6 and tried to install it but windows would not let me. Saying that I had a new version.
I tried to repair using windows installation disk. said it could not copy a file. said it was missing. Can't remember the file name off hand. qu??.dll or dl_.
I copied files from laptop to use ie. Here are the logs. Panda found a virus that is very new. It was entered into their data banks two days ago on sunday 12th.
When I looked for C:\Documents and Settings\<USER>\Application Data\Microsoft\Internet Explorer\Quick Launch there was no folder or file that fit that description. I already had show hidden files checked and hide system files unchecked.
Incident Status Location
Adware:adware/toprebates Not disinfected C:\WINDOWS\SYSTEM32\WebRebates_Broadspring1_InstallAS.exe
Adware:adware/adsmart Not disinfected C:\WINDOWS\SYSTEM32\vx.tll
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\uniq
Adware:adware/dollarrevenue Not disinfected C:\WINDOWS\timessquare1.dat
Adware:adware/vaultsearch Not disinfected C:\PROGRAM FILES\COMMON FILES\VCClient
Adware:adware/cws Not disinfected C:\Documents and Settings\Samuel L. Jackson\Favorites\Shop
Adware:adware/commad Not disinfected C:\DOCUMENTS AND SETTINGS\LOCALSERVICE\APPLICATION DATA\NetMon
Spyware:spyware/surfsidekick Not disinfected Windows Registry
Adware:Adware/TopRebates Not disinfected C:\WINDOWS\SYSTEM32\WebRebates_Broadspring1_InstallAS.exe
Spyware:Spyware/RXToolbar Not disinfected C:\WINDOWS\SYSTEM32\RXToolbar.exe
Virus:W32/Smitfraud.D Not disinfected C:\WINDOWS\SYSTEM32\wininet.old
Virus:Trj/Agent.BME Not disinfected C:\WINDOWS\SYSTEM32\sachosts.exe
Virus:Bck/Aemon.Y Not disinfected C:\WINDOWS\SYSTEM32\vxgamet4.exe26624.exe
Virus:Trj/Agent.BME Not disinfected C:\WINDOWS\SYSTEM32\sachostp.exe
Adware:Adware/Look2Me Not disinfected C:\avenger\backup.zip[dfvvox.dll]
Adware:Adware/Look2Me Not disinfected C:\avenger\backup.zip[msc42u.dll]
Virus:Trj/Ssldr32.A Not disinfected C:\avenger\backup.zip[ssldr32.dll]
Adware:Adware/Look2Me Not disinfected C:\avenger\backup.zip[andio3d.dll]
Adware:Adware/Look2Me Not disinfected C:\avenger\backup.zip[hr8405lqe.dll]
Adware:Adware/Look2Me Not disinfected C:\avenger\backup.zip[l8r00i9me8.dll]
Adware:Adware/Look2Me Not disinfected C:\avenger\backup-Sun 03.12.2006-15.16.58.09.zip[ktdlv.dll]
Virus:Trj/Agent.BME Not disinfected C:\avenger\backup-Sun 03.12.2006-15.16.58.09.zip[sachostc.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\l2mfix\Process.exe
Virus:Trj/Banker.CGV Not disinfected C:\Program Files\Microsoft AntiSpyware\DeactivatedItems\F2C61D92-F3A7-4F34-B0A7-341FEE.asq
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Mozilla Firefox\l2mfix.exe[Process.exe]
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Documents and Settings\Samuel L. Jackson\Desktop\script\hix\moo.dll
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\Documents and Settings\Samuel L. Jackson\Desktop\script\hix\scripts\systeminfo\moo.dll
Virus:mIRC/Gen Not disinfected C:\Documents and Settings\Samuel L. Jackson\Desktop\script\hix\aliases.ini
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Samuel L. Jackson\Application Data\Mozilla\Firefox\Profiles\ogvwl9ni.default\cookies.txt[]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Samuel L. Jackson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e3b1005-7939c3dc.zip[BlackBox.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Samuel L. Jackson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e3b1005-7939c3dc.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Samuel L. Jackson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e3b1005-7939c3dc.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Samuel L. Jackson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e3b1005-7939c3dc.zip[Beyond.class]
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\hixscript\hix\moo.dll
Potentially unwanted tool:Application/MotherboardMonitor.A Not disinfected C:\hixscript\hix\scripts\systeminfo\moo.dll
Virus:mIRC/Gen Not disinfected C:\hixscript\hix\aliases.ini
Potentially unwanted tool:Application/Processor Not disinfected E:\stuff\smitRem.exe[Process.exe]
Logfile of HijackThis v1.99.1
Scan saved at 11:20:34 AM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\ICQLite\ICQLite.exe
C:\WINDOWS\CTHELPER.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\eVGA\ResChanger2004\ResChanger2004.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus C62 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0BIC1.EXE /P23 "EPSON Stylus C62 Series" /O5 "LPT1:" /M "Stylus C62"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
O4 - HKLM\..\Run: [ICQ Lite] C:\Program Files\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ResChanger2004] C:\Program Files\eVGA\ResChanger2004\ResChanger2004.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Royal Vegas Poker - {FA4904B4-1FAF-4afd-886C-C19D2297BA62} - C:\Program Files\royalvegasMPP\MPPoker.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co...b?1109374976150O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: ComPlusSetup - C:\WINDOWS\system32\catsrvut.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - AHEAD Software - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe