Wow..you are truely amazing and wonderful. Looks like we got most if not all!
first..Hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 2:17:23 PM, on 12/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\E_S00RP1.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\iFtpSvc\iftpsvc.exe
C:\Program Files\Creative\ShareDLL\MediaDet.Exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\DigiPortal Software\ChoiceMail\ChoiceMail.exe
C:\Program Files\DigiPortal Software\ChoiceMail\ChoiceMail.exe
C:\Program Files\DigiPortal Software\ChoiceMail\IzyMail.exe
C:\PROGRA~1\INCRED~1\bin\ImApp.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Hijackthis\HijackThis.exe
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\prefs.js)
O3 - Toolbar: CSShell.ToolBand - {4D63CEBE-B169-426C-B092-C130C498B6E6} - C:\Program Files\ContentSaver\CSShell.dll
O3 - Toolbar: CSShell.SaveExtBand - {86B09C4E-4137-4863-B585-380205F1F774} - C:\Program Files\ContentSaver\CSShell.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [\\CHUCK\EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P38 "\\CHUCK\EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O8 - Extra context menu item: File and Save Page Area (Frame) with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#106
O8 - Extra context menu item: File and Save Picture with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#108
O8 - Extra context menu item: File and Save Selection with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#109
O8 - Extra context menu item: File and Save Target with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#107
O8 - Extra context menu item: Note Link Address with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#110
O8 - Extra context menu item: Save Page Area (Frame) with ContentSaver - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#102
O8 - Extra context menu item: Save Picture with ContentSaver - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#101
O8 - Extra context menu item: Save Selected Targets with ContentSaver... - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#111
O8 - Extra context menu item: Save Selection with ContentSaver - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#104
O8 - Extra context menu item: Save Target with ContentSaver - res://C:\PROGRA~1\CONTEN~1\csshell.dll/#103
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone:
http://www.classmates.comO15 - Trusted Zone:
http://www.mypoints.comO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v5co...b?1114566343374O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cabO16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) -
http://us-housecall.trendmicro-europe.com/...ivex/hcImpl.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/activescan/as5free/asinst.cabO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EPSON V3 Service2(03) (EPSON_PM_RPCV2_01) - SEIKO EPSON CORPORATION - C:\WINDOWS\system32\E_S00RP1.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Ipswitch WS_FTP Server (iFtpSvc) - Ipswitch, Inc. 10 Maguire Road - Suite 220 Lexington MA. 02421 - C:\iFtpSvc\iftpsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Edwido: :dance:
Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.21:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.25:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.27:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.32:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.36:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.37:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.58:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.59:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.60:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.61:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.62:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.63:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.64:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.67:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.69:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.73:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.76:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.98:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.104:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.109:C:\Documents and Settings\MOM\Application Data\Mozilla\Firefox\Profiles\ws82b4wy.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.9:C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\MOM\Application Data\Mozilla\Profiles\default\zm7r64gk.slt\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\MOM\Local Settings\Application Data\IM\Identities\{578E5DB7-A8ED-49ED-98F8-070C1ED4FE43}\Message Store\Attachments\ATT109.eml -> Dropper.Zerolin : Cleaned with backup
C:\Program Files\IncrediMail\bin\- Read our board rules -.exe -> Trojan.Agent.jh : Cleaned with backup
C:\Program Files\Internet Explorer\Connection Wizard\task32.exe -> Downloader.Darpa.c : Cleaned with backup
C:\WINDOWS\system32\popcorn72.exe -> Downloader.Small.bgv : Cleaned with backup
C:\WINDOWS\system32\upd751.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd847.exe -> Downloader.Small.bpz : Cleaned with backup
C:\WINDOWS\system32\upd97.exe -> Downloader.Small.bgv : Cleaned with backup
C:\WINDOWS\system32\upd972.exe -> Downloader.Small.bgv : Cleaned with backup
C:\WINDOWS\system32\winctrl64.exe -> Downloader.Small.awa : Cleaned with backup
::Report End
Activescan:
Incident Status Location
Adware:adware/cws.searchmeup Not disinfected C:\Documents and Settings\MOM\Desktop\2.dat
Thank you again for your time in helping me out. Looks like only one thing left and i deleted it.
i'm running a scan now at Trend Micro to see if it finds anything. Hopefully not!
I hope you have a terrific holiday! If I find anything else I'll let you know.
Cindy