Hi forum,
I had experienced the usual IE window popups even while using another browser, kept getting worse. As a first help I tried the trend micro house call but the operation usually hung. Also ran Lavasoft Adaware which maybe killed one virus called TSPY_Agent.AAYO.
The trend Micro spotted one ADW-Mirrar.AV among other viruses which I understand is a PUP. Then I found through referal. Spybot SD. I ran version 1.5.1.15 and it found and said it fixed several viruses - but then the Virtumonde showed up on additional scan checks. Message said to check with forum.
My system is XP home Ver. 2002 Service pack 1 with what is termed hot fix SP2. I don't know why but the hot fix doesn't show up on the system as the regular SP2.
Upon checking the forum, I saw there were requests to run certain programs before any posts.
So I loaded and ran the Karpersky Scanner - came up with a large file - looked like to me. It registered 23 viruses. After I saved the log file IE froze up and had to end with Task Manager. I then entered safe mode and started Spybot - (had to start it twice for some reason before it ran) It listed finding only the Virtumonde file (4 entries) and indicated it was fixed after that function was selected. Then left safe mode. I then ran the HiJack This program - but from reading the forum I saw suggestion I should change the name of the HiJackThis.exe file - so I did, and then ran it and saved file.
I saw request to paste in files, so I will try. While I'm not too familiar with virus repair - I have worked with computers - so some if it is unfamiliar.
Hopefully someone can explain how to proceed.
Thanks!
Kaspersky Report; Drive C: section
KASPERSKY ONLINE SCANNER REPORT
Thursday, October 18, 2007 5:55:11 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/10/2007
Kaspersky Anti-Virus database records: 438999
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 72415
Number of viruses found: 23
Number of infected objects: 151
Number of suspicious objects: 81
Duration of the scan process: 03:47:33
Infected Object Name / Virus Name / Last Action
C:\check_LSA7.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\core.sys.bac_a03528 Infected: Rootkit.Win32.Agent.eq skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ebqdltdb.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\iixtghyh.exe.bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\jaun_20070726[1].bac_a03528 Infected: Trojan.Win32.BHO.hj skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\jgawiluk.dll.bac_a03528 Infected: Trojan.Win32.BHO.hj skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\kacaujwx.exe.bac_a01904 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\lkjh[1].bac_a03528 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\lntilsph.exe.bac_a02788 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\pwfbhexp.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\qomkj.dll.bac_a03528 Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\rbwrpbct.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\retadpu572.exe.bac_a03528 Infected: Trojan-Downloader.Win32.Agent.dvd skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\retadpu572.exe.tmp.bac_a03528 Infected: Trojan-Downloader.Win32.Agent.dvd skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.dct skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528/stream Infected: Trojan-Downloader.Win32.Zlob.dct skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528 NSIS: infected - 2 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ukgktcau.exe.bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\UWA7P_0001_N91M0809NetInstaller.exe.bac_a03528 Infected: not-a-virus
ownloader.Win32.WinFixer.o skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a01904 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\wmgvkvvc.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528 NSIS: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\Application Data\Mozilla\Profiles\default\usep8q5q.slt\Mail\postoffice.worldnet.att.net\Inbox/[From
[Could not fit all of file]
I'm pretty sure I had word wrap off on this. There was some extra time as I had a spare copy of an older operating system on the partitioned drive D left there when I switched to a larger hard drive. I pretty much got all files out of it ; so I would plan to delete it all asap. I don't know what/why the report found locked areas (what's that?); skipped areas, and how do I get rid of Quaranteed areas?
Next HJT report:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:36 PM, on 10/18/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RunDLL32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Locator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.worldnet.att.net
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://netscape.aol.com/"); (C:\Documents and Settings\OZZIE\Application Data\Mozilla\Profiles\default\usep8q5q.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OZZIE\Application Data\Mozilla\Profiles\default\usep8q5q.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EDAD203-C9CD-4DD1-9AC6-EA40F50B684A} - (no file)
O2 - BHO: CSMHelperObj Class - {0F660F64-F4C9-477F-8529-44181B717472} - C:\Program Files\AT&T\WnClient\Programs\CSMBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\System32\fdymcgmb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {CC0516E8-9977-419F-B9B3-E84D0C4ABF10} - C:\WINDOWS\System32\hgdcd.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\System32\mdqpqkwa.dll",sitypnow
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\System32\RunDLL32.exe C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNow
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AnyWho - {0264505A-6793-44E0-AC75-9DCE3B13185C} - C:\Program Files\AT&T\WnClient\Programs\AnyWho.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.worldnet.att.net
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/10d382795368a9ba3923/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
O20 - Winlogon Notify: pmnopqo - C:\WINDOWS\SYSTEM32\pmnopqo.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 5828 bytes
Any thoughts on the above problem with help or explaination would be most appreciated.
Thanks again - owenisch
I had experienced the usual IE window popups even while using another browser, kept getting worse. As a first help I tried the trend micro house call but the operation usually hung. Also ran Lavasoft Adaware which maybe killed one virus called TSPY_Agent.AAYO.
The trend Micro spotted one ADW-Mirrar.AV among other viruses which I understand is a PUP. Then I found through referal. Spybot SD. I ran version 1.5.1.15 and it found and said it fixed several viruses - but then the Virtumonde showed up on additional scan checks. Message said to check with forum.
My system is XP home Ver. 2002 Service pack 1 with what is termed hot fix SP2. I don't know why but the hot fix doesn't show up on the system as the regular SP2.
Upon checking the forum, I saw there were requests to run certain programs before any posts.
So I loaded and ran the Karpersky Scanner - came up with a large file - looked like to me. It registered 23 viruses. After I saved the log file IE froze up and had to end with Task Manager. I then entered safe mode and started Spybot - (had to start it twice for some reason before it ran) It listed finding only the Virtumonde file (4 entries) and indicated it was fixed after that function was selected. Then left safe mode. I then ran the HiJack This program - but from reading the forum I saw suggestion I should change the name of the HiJackThis.exe file - so I did, and then ran it and saved file.
I saw request to paste in files, so I will try. While I'm not too familiar with virus repair - I have worked with computers - so some if it is unfamiliar.
Hopefully someone can explain how to proceed.
Thanks!
Kaspersky Report; Drive C: section
KASPERSKY ONLINE SCANNER REPORT
Thursday, October 18, 2007 5:55:11 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 18/10/2007
Kaspersky Anti-Virus database records: 438999
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 72415
Number of viruses found: 23
Number of infected objects: 151
Number of suspicious objects: 81
Duration of the scan process: 03:47:33
Infected Object Name / Virus Name / Last Action
C:\check_LSA7.txt Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\core.sys.bac_a03528 Infected: Rootkit.Win32.Agent.eq skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ebqdltdb.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a00172 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01548 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a01904 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a02788 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03436 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[1].cab.bac_a03528 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436/UERS_9999_N91S1502NetInstaller.exe Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436 CAB: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ErrorSafeFreeInstallW[2].cab.bac_a03436 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\iixtghyh.exe.bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\jaun_20070726[1].bac_a03528 Infected: Trojan.Win32.BHO.hj skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\jgawiluk.dll.bac_a03528 Infected: Trojan.Win32.BHO.hj skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\kacaujwx.exe.bac_a01904 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\lkjh[1].bac_a03528 Infected: Trojan-Downloader.Win32.Tiny.id skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\lntilsph.exe.bac_a02788 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\pwfbhexp.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\qomkj.dll.bac_a03528 Infected: not-a-virus:AdWare.Win32.Virtumonde.kr skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\rbwrpbct.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\retadpu572.exe.bac_a03528 Infected: Trojan-Downloader.Win32.Agent.dvd skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\retadpu572.exe.tmp.bac_a03528 Infected: Trojan-Downloader.Win32.Agent.dvd skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528/stream/data0006 Infected: Trojan-Downloader.Win32.Zlob.dct skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528/stream Infected: Trojan-Downloader.Win32.Zlob.dct skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528 NSIS: infected - 2 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\say8fb4a.php.bac_a03528 CryptFF.b: infected - 2 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\ukgktcau.exe.bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\UWA7P_0001_N91M0809NetInstaller.exe.bac_a03528 Infected: not-a-virus
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a01904 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a03436 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\valera[1].bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\wmgvkvvc.exe.bac_a03528 Infected: Trojan.Win32.Agent.bck skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528 NSIS: infected - 1 skipped
C:\Documents and Settings\Ozzie\.housecall6.6\Quarantine\yazzlesnet.exe.bac_a03528 CryptFF.b: infected - 1 skipped
C:\Documents and Settings\Ozzie\Application Data\Mozilla\Profiles\default\usep8q5q.slt\Mail\postoffice.worldnet.att.net\Inbox/[From
[Could not fit all of file]
I'm pretty sure I had word wrap off on this. There was some extra time as I had a spare copy of an older operating system on the partitioned drive D left there when I switched to a larger hard drive. I pretty much got all files out of it ; so I would plan to delete it all asap. I don't know what/why the report found locked areas (what's that?); skipped areas, and how do I get rid of Quaranteed areas?
Next HJT report:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:41:36 PM, on 10/18/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\RunDLL32.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\Locator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.worldnet.att.net
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://netscape.aol.com/"); (C:\Documents and Settings\OZZIE\Application Data\Mozilla\Profiles\default\usep8q5q.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNETSCAPE%5CNETSCAPE%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\OZZIE\Application Data\Mozilla\Profiles\default\usep8q5q.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EDAD203-C9CD-4DD1-9AC6-EA40F50B684A} - (no file)
O2 - BHO: CSMHelperObj Class - {0F660F64-F4C9-477F-8529-44181B717472} - C:\Program Files\AT&T\WnClient\Programs\CSMBHO.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {89AD4D75-2429-462e-BD4E-443F233F6033} - C:\WINDOWS\System32\fdymcgmb.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {CC0516E8-9977-419F-B9B3-E84D0C4ABF10} - C:\WINDOWS\System32\hgdcd.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\System32\mdqpqkwa.dll",sitypnow
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINDOWS\System32\RunDLL32.exe C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNow
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AnyWho - {0264505A-6793-44E0-AC75-9DCE3B13185C} - C:\Program Files\AT&T\WnClient\Programs\AnyWho.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.worldnet.att.net
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://207.188.7.150/10d382795368a9ba3923/netzip/RdxIE601.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} - http://toolbar.google.com/data/GoogleActivate.cab
O16 - DPF: {B7D07999-2ADB-4AEB-997E-F61CB7B2E2CD} (TSEasyInstallX Control) - http://www.trendsecure.com/easy_install/_activex/en-US/TSEasyInstallX.CAB
O20 - Winlogon Notify: pmnopqo - C:\WINDOWS\SYSTEM32\pmnopqo.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
--
End of file - 5828 bytes
Any thoughts on the above problem with help or explaination would be most appreciated.
Thanks again - owenisch