Hi, Have followed instructions.
Comments
1 I'll keep the infected file quarantined, as it/they have been stored on my computer/s for several years and to date have not
caused a problem, thanks for the advice.
2 No changes made in Folder Options as these are my default settings.
3 Unable to locate these folders/files
E:\Program Files\SpywareBot\ <<< delete that folder
D:\WINDOWS\system32\sfeojlyl.dll <<< delete that file
These Were gone after HJT instructions followed.
4 AVG Scan report below
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 23:38:45 20/04/2007
+ Scan result:
E:\System Volume Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP40\A0009195.exe -> Adware.DashBar : Cleaned.
D:\System Volume Information\_restore{C461DE8B-E17A-4A6F-A17F-1F19B7A00179}\RP2\A0000337.exe ->
Not-A-Virus.Downloader.Win32.ImLoader.b : Cleaned.
E:\System Volume Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP11\A0005823.exe ->
Not-A-Virus.Downloader.Win32.ImLoader.b : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@track.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
D:\Documents and Settings\kmjas\Cookies\kmjas@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
::Report end
5 HJT Report
Logfile of HijackThis v1.99.1
Scan saved at 00:08:02, on 21/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
C:\VirusCleaning\AVG Anti-Spyware 7.5\guard.exe
E:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
D:\WINDOWS\system32\CTsvcCDA.EXE
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
E:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
D:\WINDOWS\system32\MsPMSPSv.exe
D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
E:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
E:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
D:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
D:\Program Files\Microsoft IntelliPoint\ipoint.exe
D:\Program Files\Windows Defender\MSASCui.exe
D:\WINDOWS\system32\devldr32.exe
E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\VirusCleaning\AVG Anti-Spyware 7.5\avgas.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\wuauclt.exe
E:\Program Files\Microsoft ActiveSync\Wcescomm.exe
E:\PROGRA~1\MICROS~2\rapimgr.exe
E:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe
D:\Opera\Opera.exe
D:\PROGRA~1\BXNEWF~1\bxExpHelper.exe
D:\WINDOWS\system32\NOTEPAD.EXE
C:\VirusCleaning\HijackThis.exe
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] D:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [cctray] "E:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "E:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [EEventManager] D:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
O4 - HKLM\..\Run: [IntelliPoint] "d:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "E:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\VirusCleaning\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] D:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Skype] "D:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [H/PC Connection Agent] "E:\Program Files\Microsoft ActiveSync\Wcescomm.exe"
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://E:\Program Files\Adobe\Acrobat
7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - E:\PROGRA~1\MICROS~2\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - D:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\VirusCleaning\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - E:\Program Files\CA\CA Internet Security Suite\CA
Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - D:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - E:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
6. While the AVG scan was running CA Anti Virus reported the following.
2007/04/20 23:07:10.546 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008935.dll is Win32/Vundo!generic trojan. Deleted
2007/04/20 23:07:11.406 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008935.dll is Win32/Vundo!generic trojan.
2007/04/20 23:07:12.171 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008935.dll is Win32/Vundo!generic trojan.
2007/04/20 23:07:25.578 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP40\A0009223.exe is Win32/Chisyne.BC trojan. Deleted
2007/04/20 23:07:27.046 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP40\A0009223.exe is Win32/Chisyne.BC trojan.
2007/04/20 23:07:27.796 File infection: D:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP40\A0009223.exe is Win32/Chisyne.BC trojan.
2007/04/20 23:33:32.156 File infection: E:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008787.exe is Win32/Chisyne.BC trojan. Deleted
2007/04/20 23:33:32.828 File infection: E:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008787.exe is Win32/Chisyne.BC trojan.
2007/04/20 23:33:32.953 File infection: E:\System Volume
Information\_restore{DFA7E683-0066-4EE3-BF19-ECC1AA4C6918}\RP37\A0008787.exe is Win32/Chisyne.BC trojan.
7. Have just opened IE, and the same problem still exists, my default page About.Blank, Went to Google and as soon as Google opened, there was internet activity and the the following page opened, unrequested.
http://www.systemdoctor.com/downloa...a98_aca45c33+1d70394b380f461c817b3d1b69deb8f3
Seems like I can only use Opera with any degree of safety.
Back to you for comments.
Thanks