hi,
i ran through the Preliminary Steps, and it looks like that the problem was solved but i would just like to make sure.
here is my log files:
Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 7:44:29 PM, on 25/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Vet\isafe.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Vet\VetMsg.exe
C:\Vet\VetTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ccleaner] "D:\Program Files\CCleaner\ccleaner.exe" /AUTO
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe
>>>Online scan:
Incident Status Location
Virus:Trj/DisableKey.A Disinfected Operating system
Virus:Trj/DisableKey.A Disinfected Operating system
Adware:adware/pornmagpass Not disinfected c:\windows\system32\ishost.exe
Adware:adware/systemdoctor Not disinfected c:\windows\system32\isnotify.exe
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/sidesearch Not disinfected Windows Registry
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\u9d9xxdt.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\User\Cookies\user@stats1.reliablestats[2].txt
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b124.exe[²ÜÇ\nsRandom.dll]
Potentially unwanted tool:Application/SpywareQuake Not disinfected C:\Documents and Settings\User\Local Settings\Temp\sa25.exe[Spy-Quake2.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\User\Local Settings\Temp\totauukv.dll
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\User\Local Settings\Temp\win19.tmp.exe
Virus:Trj/DisableKey.A Disinfected C:\Documents and Settings\User\Local Settings\Temp\win1E.tmp.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{943B1724-0AFD-3081-0302-04060313003d}\services.dll
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\components\flx7.dll
Virus:Trj/DisableKey.A Disinfected C:\WINDOWS\system32\uhvjsul.dll
Virus:Trj/DisableKey.A Disinfected C:\WINDOWS\system32\unaoakg.dll
Adware:Adware/SpywareQuake Not disinfected C:\WINDOWS\system32\urroxtl.dll
i ran through the Preliminary Steps, and it looks like that the problem was solved but i would just like to make sure.
here is my log files:
Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 7:44:29 PM, on 25/09/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Vet\isafe.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Vet\VetMsg.exe
C:\Vet\VetTray.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
O4 - HKLM\..\Run: [VetTray] C:\Vet\VetTray.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKCU\..\Run: [ccleaner] "D:\Program Files\CCleaner\ccleaner.exe" /AUTO
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\Vet\isafe.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Vet\VetMsg.exe
>>>Online scan:
Incident Status Location
Virus:Trj/DisableKey.A Disinfected Operating system
Virus:Trj/DisableKey.A Disinfected Operating system
Adware:adware/pornmagpass Not disinfected c:\windows\system32\ishost.exe
Adware:adware/systemdoctor Not disinfected c:\windows\system32\isnotify.exe
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Adware:adware/sidesearch Not disinfected Windows Registry
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\u9d9xxdt.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\User\Cookies\user@stats1.reliablestats[2].txt
Adware:Adware/PCodec Not disinfected C:\Documents and Settings\User\Local Settings\Temp\b124.exe[²ÜÇ\nsRandom.dll]
Potentially unwanted tool:Application/SpywareQuake Not disinfected C:\Documents and Settings\User\Local Settings\Temp\sa25.exe[Spy-Quake2.exe]
Spyware:Spyware/Virtumonde Not disinfected C:\Documents and Settings\User\Local Settings\Temp\totauukv.dll
Adware:Adware/Maxifiles Not disinfected C:\Documents and Settings\User\Local Settings\Temp\win19.tmp.exe
Virus:Trj/DisableKey.A Disinfected C:\Documents and Settings\User\Local Settings\Temp\win1E.tmp.exe
Spyware:Spyware/Virtumonde Not disinfected C:\Program Files\Common Files\{943B1724-0AFD-3081-0302-04060313003d}\services.dll
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\system32\components\flx7.dll
Virus:Trj/DisableKey.A Disinfected C:\WINDOWS\system32\uhvjsul.dll
Virus:Trj/DisableKey.A Disinfected C:\WINDOWS\system32\unaoakg.dll
Adware:Adware/SpywareQuake Not disinfected C:\WINDOWS\system32\urroxtl.dll