Hi there,
Thank you for that. Unfortunately no change in hotmail. Please find correct Bit Defender log and latest HJT log below.
Thank you again,
Operaboy.
BitDefender Online Scanner
Scan report generated at: Tue, Nov 29, 2005 - 13:14:55
Scan path: A:\;C:\;D:\;E:\;
Statistics
Time
02:50:05
Files
355867
Folders
3811
Boot Sectors
2
Archives
3612
Packed Files
35302
Results
Identified Viruses
3
Infected Files
4
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
4
Engines Info
Virus Definitions
236422
Engine build
AVCORE v1.0 (build 2292) (i386) (Mar 3 2005 11:57:29)
Scan plugins
13
Archive plugins
38
Unpack plugins
4
E-mail plugins
6
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\My Documents\My Pictures\mechanic-2.2.exe=>(NSIS o)=>lzma_nsis0007
Infected with: Dropped:Trojan.Click.337
C:\My Documents\My Pictures\mechanic-2.2.exe=>(NSIS o)=>lzma_nsis0007
Disinfection failed
C:\My Documents\My Pictures\mechanic-2.2.exe=>(NSIS o)=>lzma_nsis0007
Deleted
C:\My Documents\My Pictures\mechanic-2.2.exe=>(NSIS o)
Update failed
C:\Program Files\Common Files\mozilla.org\GRE\1.7.2_2004080415\omsetup.exe =>wise0025=>wise0024
Infected with: Backdoor.Optix.Pro.1
C:\Program Files\Common Files\mozilla.org\GRE\1.7.2_2004080415\omsetup.exe =>wise0025=>wise0024
Disinfection failed
C:\Program Files\Common Files\mozilla.org\GRE\1.7.2_2004080415\omsetup.exe =>wise0025=>wise0024
Deleted
C:\Program Files\Common Files\mozilla.org\GRE\1.7.2_2004080415\omsetup.exe =>wise0025
Update failed
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0002
Infected with: Trojan.Dropper.Agent.KQ
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0002
Disinfection failed
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0002
Deleted
C:\Downloads\Software\daemon347.exe=>(NSIS o)
Update failed
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0003
Infected with: Trojan.Dropper.Agent.KQ
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0003
Disinfection failed
C:\Downloads\Software\daemon347.exe=>(NSIS o)=>lzma_nsis0003
Deleted
C:\Downloads\Software\daemon347.exe=>(NSIS o)
Update failed
Logfile of HijackThis v1.99.0
Scan saved at 1:29:47 PM, on 29/11/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\CTFMON.EXE
C:\PROGRAM FILES\NETGEAR WG311V2 ADAPTER\WLANCFG5.EXE
C:\WINDOWS\SYSTEM\LEXBCES.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\LEXPPS.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
https://loginnet.passport.com/ppsecu...th.srf?lc=1033
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\y0lfc6nq.slt\prefs.j s)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\y0lfc6nq.slt\prefs.j s)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 6.0\READER\ACTIVEX\ACROIEHELPER.DLL
O2 - BHO: FoxieSecurityModule Class - {C65185B1-D52B-44A9-861F-8201B50D1F37} - C:\PROGRAM FILES\FOXIE SUITE\FOXIECORE.DLL
O2 - BHO: FoxieToolbar Class - {432CAE3B-690F-4C3B-BD97-070EBDA210D5} - C:\PROGRAM FILES\FOXIE SUITE\FOXIETOOLBAR.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\PROGRAM FILES\FOXIE SUITE\FOXIECORE.DLL
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [LexStart] lexstart.exe
O4 - HKLM\..\RunServices: [MDM7] "C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\VS7DEBUG\MDM.EXE"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: NETGEAR WG311v2 Smart Configuration.lnk = C:\Program Files\NETGEAR WG311v2 Adapter\wlancfg5.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE10\EXCEL.EXE/3000
O8 - Extra context menu item: Download by Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Download web site by Free Download Manager - file://C:\Program Files\Free Download Manager\dlpage.htm
O8 - Extra context menu item: Download all by Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected by Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: &Google Search - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsearch.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmsimilar.html
O8 - Extra context menu item: Backward Links - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmbacklinks.html
O8 - Extra context menu item: Translate into English - res://C:\PROGRAM FILES\GOOGLE\GOOGLETOOLBAR1.DLL/cmtrans.html
O9 - Extra button: Pardon - {302172A1-A2B4-4402-B1D0-F5D54C3E83C6} - C:\Program Files\Pardon 3\Pardon.exe
O9 - Extra 'Tools' menuitem: Pardon - {302172A1-A2B4-4402-B1D0-F5D54C3E83C6} - C:\Program Files\Pardon 3\Pardon.exe
O9 - Extra button: AAPT Mobile Communicator - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\AAPT Mobile Communicator\mcommunicate.exe (file missing)
O9 - Extra 'Tools' menuitem: AAPT Mobile Communicator - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\AAPT Mobile Communicator\mcommunicate.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: AAPT Mobile Communicator - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\AAPT Mobile Communicator\MCommunicate.exe (file missing) (HKCU)
O9 - Extra 'Tools' menuitem: AAPT Mobile Communicator - {4B3520B0-D518-4443-BA9E-2D4CE7F773C5} - C:\Program Files\AAPT Mobile Communicator\MCommunicate.exe (file missing) (HKCU)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -
http://download.bitdefender.com/reso...an8/oscan8.cab