It appears my Internet Explorer Home Page and the Search capability have been infiltrated with some kind of malware. Specifically, the home page is sometimes changed and the Google search gets re-routed. I would appreciate any assistance in identifying the harmful item(s) as well as in ridding the computer of such items.
I ran the Panda online scan and it has identified a number of things. The log report follows:
Incident Status Location
Adware:adware/thespyguard Not disinfected c:\windows\system32\shellgui32.dll
Adware:adware/admess Not disinfected c:\windows\system32\tcpservice2.exe
Adware:adware/topspyware Not disinfected c:\windows\system32\txfdb32.dll
Adware:adware/btgrab Not disinfected c:\windows\BTGrab.dll
Adware:adware/transponder Not disinfected c:\windows\dlmax.dll
Spyware:spyware/betterinet Not disinfected c:\windows\susp.exe
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-5f8e179f-42f90fe5.class
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2a880e3-28be3a9a.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-3bac9472-5b989350.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-42c10434-79d976c3.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4630bc5-2c77895a.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4966bd13-5381ae97.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5000a103-70c58001.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-684ecb1c-47bf5918.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-19e7a114-3a4455d3.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-289411a6-413430f4.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2fa0daf-4ae8e1a8.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-550635dc.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-5075da91-46890e67.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-51ba0579-722c24d6.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-522ce96a-75e71ce7.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-853957b-3b921c8d.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-8f71a21-49f49211.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-752c5747-221d2b55.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-dac4642-33208bf4.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count3.jar-2a1f473-5e9f605d.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv537.jar-69d0c3ee-5c47791e.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv537.jar-69d0c3ee-5c47791e.zip[Matrix.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv79.jar-277f5f16-272796be.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv79.jar-277f5f16-272796be.zip[Matrix.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a26-5c94216f.zip[Gummy.class]
Virus:Trj/ClassLoader.E Disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-12139981.zip[SuperMSClassLoader.class]
Virus:Trj/ClassLoader.E Disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-12139981.zip[NewURLClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-2a8d8764.zip[NewSecurityClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-2a8d8764.zip[NewURLClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv493.jar-1661bf12-54db33af.zip[Dummy.class]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Janet Galley\Cookies\janet galley@tribalfusion[2].txt
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Inbox\Mail Delivery (failure dgalley@cansling.com)
Virus:Trj/dmRandom.FE Disinfected C:\WINDOWS\system32\kdrkd.exe
As well, I ran the Hijackthis program - it will follow in the next post.
Thanks so much.
I ran the Panda online scan and it has identified a number of things. The log report follows:
Incident Status Location
Adware:adware/thespyguard Not disinfected c:\windows\system32\shellgui32.dll
Adware:adware/admess Not disinfected c:\windows\system32\tcpservice2.exe
Adware:adware/topspyware Not disinfected c:\windows\system32\txfdb32.dll
Adware:adware/btgrab Not disinfected c:\windows\BTGrab.dll
Adware:adware/transponder Not disinfected c:\windows\dlmax.dll
Spyware:spyware/betterinet Not disinfected c:\windows\susp.exe
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\Dummy.class-5f8e179f-42f90fe5.class
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-2a880e3-28be3a9a.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-3bac9472-5b989350.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-42c10434-79d976c3.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4630bc5-2c77895a.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-4966bd13-5381ae97.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-5000a103-70c58001.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ar3.jar-684ecb1c-47bf5918.zip[Gummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-19e7a114-3a4455d3.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-289411a6-413430f4.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2fa0daf-4ae8e1a8.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-32e447f4-550635dc.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-5075da91-46890e67.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-51ba0579-722c24d6.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-522ce96a-75e71ce7.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-853957b-3b921c8d.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-8f71a21-49f49211.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-752c5747-221d2b55.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive1213.jar-dac4642-33208bf4.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count3.jar-2a1f473-5e9f605d.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv537.jar-69d0c3ee-5c47791e.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv537.jar-69d0c3ee-5c47791e.zip[Matrix.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv79.jar-277f5f16-272796be.zip[Dummy.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Don Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv79.jar-277f5f16-272796be.zip[Matrix.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-44f46a26-5c94216f.zip[Gummy.class]
Virus:Trj/ClassLoader.E Disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-12139981.zip[SuperMSClassLoader.class]
Virus:Trj/ClassLoader.E Disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\ie0601a.jar-523da84a-12139981.zip[NewURLClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-2a8d8764.zip[NewSecurityClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\java.jar-7e09d0a6-2a8d8764.zip[NewURLClassLoader.class]
Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Janet Galley\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv493.jar-1661bf12-54db33af.zip[Dummy.class]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Janet Galley\Cookies\janet galley@tribalfusion[2].txt
Hacktool:Exploit/iFrame Not disinfected Personal Folders\Inbox\Mail Delivery (failure dgalley@cansling.com)
Virus:Trj/dmRandom.FE Disinfected C:\WINDOWS\system32\kdrkd.exe
As well, I ran the Hijackthis program - it will follow in the next post.
Thanks so much.