Hi Jane,
I got your three responses (thanks very much), and I'll reply by number below:
1. I sent you the zip, and I have received your response that it is infected :( .
******************
2. I found two files called "hosts" (and what I think are two related files called "lmhosts"). However, I kept getting a message that windows couldn't open them, so I can't paste the contents.
****************
3. I ran the most recent AAW, and it didn't turn up anything. The log is below:
Lavasoft Ad-aware Personal Build 6.181
Logfile created on :Saturday, April 24, 2004 8:22:22 PM
Created with Ad-aware Personal, free for private use.
Using reference-file :01R299 22.04.2004
______________________________________________________
Ad-aware Settings
=========================
Set : Activate in-depth scan (Recommended)
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
4-24-2004 8:22:22 PM - Scan started. (Custom mode)
Listing running processes
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ThreadCreationTime : 4-24-2004 12:16:47 PM
BasePriority : Normal
#:2 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:51 PM
BasePriority : High
#:3 [services.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:51 PM
BasePriority : Normal
FileSize : 99 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Services and Controller app
InternalName : services.exe
OriginalFilename : services.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/29/2002 11:00:00 AM
#:4 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:51 PM
BasePriority : Normal
FileSize : 11 KB
FileVersion : 5.1.2600.1106 (xpsp1.020828-1920)
ProductVersion : 5.1.2600.1106
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
OriginalFilename : lsass.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/29/2002 11:00:00 AM
#:5 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:52 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:04:27 AM
Last modified : 8/29/2002 11:00:00 AM
#:6 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-24-2004 12:16:52 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:04:27 AM
Last modified : 8/29/2002 11:00:00 AM
#:7 [explorer.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 4-24-2004 12:16:53 PM
BasePriority : Normal
FileSize : 980 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
OriginalFilename : EXPLORER.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/29/2002 11:00:00 AM
#:8 [lexbces.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:54 PM
BasePriority : Normal
FileSize : 296 KB
FileVersion : 8.16
ProductVersion : 8.16
Copyright : © 1993 - 2003 Lexmark International, Inc.
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
OriginalFilename : LexBceS.exe
ProductName : MarkVision for Windows (32 bit)
Created on : 6/2/2003 4:01:26 PM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 6/2/2003 4:01:26 PM
#:9 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:54 PM
BasePriority : Normal
FileSize : 50 KB
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
OriginalFilename : spoolsv.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/29/2002 11:00:00 AM
#:10 [lexpps.exe]
FilePath : C:\WINDOWS\system32\
ThreadCreationTime : 4-24-2004 12:16:54 PM
BasePriority : Normal
FileSize : 170 KB
FileVersion : 8.16
ProductVersion : 8.16
Copyright : © 1993 - 2003 Lexmark International, Inc.
CompanyName : Lexmark International, Inc.
FileDescription : LEXPPS.EXE
InternalName : LEXPPS
OriginalFilename : LEXPPS.EXE
ProductName : MarkVision for Windows (32 bit)
Created on : 6/2/2003 3:56:02 PM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 6/2/2003 3:56:02 PM
#:11 [hkcmd.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-24-2004 12:16:55 PM
BasePriority : Normal
FileSize : 112 KB
FileVersion : 3,0,0,2104
ProductVersion : 7,0,0,2104
Copyright : Copyright 1999-2003, Intel Corporation
CompanyName : Intel Corporation
FileDescription : hkcmd Module
InternalName : HKCMD
OriginalFilename : HKCMD.EXE
ProductName : Intel® Common User Interface
Created on : 1/1/1980 6:00:00 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 4/7/2003 6:07:38 AM
#:12 [tfswctrl.exe]
FilePath : C:\WINDOWS\system32\dla\
ThreadCreationTime : 4-24-2004 12:16:55 PM
BasePriority : Normal
FileSize : 112 KB
FileVersion : 1.04.05b
Copyright : Copyright
CompanyName : Sonic Solutions
FileDescription : Drive Letter Access Component
Created on : 1/6/2004 1:26:18 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/6/2003 7:04:00 AM
#:13 [dsentry.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-24-2004 12:16:55 PM
BasePriority : Normal
FileSize : 28 KB
FileVersion : 1, 0, 5, 0
ProductVersion : 1, 0, 5, 0
Copyright : Copyright
CompanyName : Dell - Advanced Desktop Engineering
FileDescription : DVDSentry
InternalName : DVDSentry
OriginalFilename : DSentry.exe
ProductName : Dell - DVDSentry
Created on : 8/13/2003 4:27:40 PM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/13/2003 4:27:40 PM
#:14 [pcmservice.exe]
FilePath : C:\Program Files\Dell\Media Experience\
ThreadCreationTime : 4-24-2004 12:16:56 PM
BasePriority : Normal
FileSize : 200 KB
FileVersion : 1.0.0826
ProductVersion : 1.0.0826
Copyright : Copyright c 2003 CyberLink Corp.
CompanyName : CyberLink Corp.
FileDescription : PowerCinema Resident Program for Dell
InternalName : PowerCinema Resident Program for Dell
OriginalFilename : PCM2Launcher.EXE
ProductName : PCM2Launcher Application
Created on : 1/6/2004 1:29:18 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 8/27/2003 1:47:34 AM
#:15 [mmtask.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 4-24-2004 12:16:57 PM
BasePriority : Normal
FileSize : 52 KB
FileVersion : 1.0.0.1
ProductVersion : 1.0.0.1
Copyright : TODO: © <Company name>. All rights reserved.
CompanyName : TODO: <Company name>
FileDescription : TODO: <File description>
InternalName : mmtask.exe
OriginalFilename : mmtask.exe
ProductName : TODO: <Product name>
Created on : 3/4/2004 3:01:49 AM
Last accessed : 4/25/2004 12:22:22 AM
Last modified : 1/26/2004 3:46:48 PM
#:16 [support.exe]
FilePath : C:\Program Files\Common Files\Dell\EUSW\
ThreadCreationTime : 4-24-2004 12:16:57 PM
BasePriority : Normal
FileSize : 288 KB
FileVersion : 2, 0, 0, 34
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : Dell
FileDescription : Support
InternalName : Support
OriginalFilename : Support.exe
ProductName : Dell Support
Created on : 10/7/2003 10:21:10 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 10/7/2003 10:21:10 PM
#:17 [ipodmanager.exe]
FilePath : C:\Program Files\iPod\bin\
ThreadCreationTime : 4-24-2004 12:16:57 PM
BasePriority : Normal
FileSize : 240 KB
FileVersion : 1.0.30.0
ProductVersion : 2.0.1?0
Copyright : Copyright
FileDescription : iPodManager Module
InternalName : iPodManager
OriginalFilename : iPodManager.EXE
ProductName : iPodManager Module
Created on : 6/15/2003 12:54:46 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 6/15/2003 12:54:46 PM
#:18 [mm_tray.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 4-24-2004 12:16:58 PM
BasePriority : Normal
FileSize : 116 KB
FileVersion : 8.20.0107
ProductVersion : 8.20.0107
Copyright : Copyright
CompanyName : MUSICMATCH, Inc.
FileDescription : mm_tray
InternalName : mm_tray
OriginalFilename : mm_tray.exe
ProductName : MUSICMATCH JUKEBOX
Created on : 1/10/2004 6:02:28 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 1/26/2004 3:46:48 PM
#:19 [dlbkbmgr.exe]
FilePath : C:\Program Files\Dell AIO Printer A920\
ThreadCreationTime : 4-24-2004 12:16:58 PM
BasePriority : Normal
FileSize : 264 KB
FileVersion : 0.1.1.1
ProductVersion : 0.1.1.1
CompanyName : Dell Computer Corporation
FileDescription : Dell AIO Printer A920Button Manager
InternalName : dlbkbmgr.exe
OriginalFilename : dlbkbmgr.exe
ProductName : Button Manager Executable
Created on : 6/2/2003 6:25:24 PM
Last accessed : 4/25/2004 12:17:03 AM
Last modified : 6/2/2003 6:25:24 PM
#:20 [notifyalert.exe]
FilePath : C:\Program Files\Dell\Support\Alert\bin\
ThreadCreationTime : 4-24-2004 12:16:58 PM
BasePriority : Normal
FileSize : 344 KB
FileVersion : 2.1.0.72
ProductVersion : 2.1.0.72
InternalName : NotifyAlert.exe
OriginalFilename : NotifyAlert.exe
Created on : 10/7/2003 10:20:18 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 10/7/2003 10:20:18 PM
#:21 [mscifapp.exe]
FilePath : C:\Program Files\McAfee.com\MPS\
ThreadCreationTime : 4-24-2004 12:16:58 PM
BasePriority : Normal
FileSize : 220 KB
FileVersion : 4, 0, 1, 24
ProductVersion : 4, 0, 0, 0
Copyright : Copyright
CompanyName : Networks Associates Technology, Inc
FileDescription : McAfee Privacy Service
InternalName : mscifapp
OriginalFilename : mscifapp.exe
ProductName : McAfee Privacy Service
Created on : 2/5/2004 2:35:44 AM
Last accessed : 4/24/2004 11:31:44 PM
Last modified : 7/25/2003 8:56:18 PM
#:22 [dlbkbmon.exe]
FilePath : C:\Program Files\Dell AIO Printer A920\
ThreadCreationTime : 4-24-2004 12:16:58 PM
BasePriority : Normal
FileSize : 52 KB
FileVersion : 0.1.1.1
ProductVersion : 0.1.1.1
CompanyName : Dell Computer Corporation
FileDescription : Dell AIO Printer A920Button Monitor
InternalName : dlbkbmon.exe
OriginalFilename : dlbkbmon.exe
ProductName : Button Monitor Executable
Created on : 6/2/2003 6:50:58 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 6/2/2003 6:50:58 PM
#:23 [mpftray.exe]
FilePath : C:\PROGRA~1\McAfee.com\PERSON~1\
ThreadCreationTime : 4-24-2004 12:16:59 PM
BasePriority : Normal
FileSize : 1348 KB
FileVersion : 5.0.1.5
ProductVersion : 5.0.1.5
Copyright : Copyright
CompanyName : McAfee Security
FileDescription : McAfee Personal Firewall Tray Monitor
InternalName : MpfTray
OriginalFilename : MPFTRAY.EXE
ProductName : McAfee Personal Firewall (MPF)
Created on : 1/31/2004 3:25:48 AM
Last accessed : 4/25/2004 12:17:46 AM
Last modified : 9/2/2003 7:00:00 PM
#:24 [wkufind.exe]
FilePath : C:\Program Files\Common Files\Microsoft Shared\Works Shared\
ThreadCreationTime : 4-24-2004 12:16:59 PM
BasePriority : Normal
FileSize : 28 KB
FileVersion : 7.00.0716.0
ProductVersion : 7.00.0716.0
Copyright : Copyright
CompanyName : Microsoft
FileDescription : Microsoft
InternalName : WkUFind
OriginalFilename : WkUFind.exe
ProductName : Update Detection Module
Created on : 7/16/2002 1:21:48 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 7/16/2002 1:21:48 PM
#:25 [mnyexpr.exe]
FilePath : C:\Program Files\Microsoft Money\System\
ThreadCreationTime : 4-24-2004 12:16:59 PM
BasePriority : Normal
FileSize : 196 KB
FileVersion : 11.00.0716
ProductVersion : 11.00.0716
Copyright : Copyright © Microsoft Corp. 1990-2001. All rights reserved.
CompanyName : Microsoft Corporation
FileDescription : Microsoft Money Express
InternalName : mnyexpr
OriginalFilename : mnyexpr.exe
ProductName : Microsoft Money
Created on : 7/17/2002 5:00:00 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 7/17/2002 5:00:00 PM
#:26 [histkill.exe]
FilePath : C:\Program Files\HistoryKill\
ThreadCreationTime : 4-24-2004 12:16:59 PM
BasePriority : Normal
FileSize : 251 KB
FileVersion : 2003.01.0003
ProductVersion : 2003.01.0003
Copyright : © Copyright SwankSoft Technologies, Inc. 1998-2003
CompanyName : SwankSoft Technologies, Inc.
FileDescription : HistoryKill privacy utility
InternalName : histkill
OriginalFilename : histkill.exe
ProductName : HistoryKill
Created on : 1/18/2003 8:49:14 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 10/10/2003 7:27:20 AM
#:27 [aoltray.exe]
FilePath : C:\Program Files\America Online 9.0\
ThreadCreationTime : 4-24-2004 12:17:00 PM
BasePriority : Normal
FileSize : 36 KB
FileVersion : 9.00.000
ProductVersion : 9.00.000
Copyright : Copyright © America Online, Inc. 1999 - 2003
CompanyName : America Online, Inc.
FileDescription : AOL Tray Icon
InternalName : AolTray
ProductName : America Online
Created on : 1/6/2004 1:30:20 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 8/9/2003 11:36:04 PM
#:28 [hkpopupkiller.exe]
FilePath : C:\Program Files\HistoryKill\
ThreadCreationTime : 4-24-2004 12:17:02 PM
BasePriority : Normal
FileSize : 152 KB
FileVersion : 2003.01.0003
ProductVersion : 2003.01.0003
Copyright : SwankSoft Technologies, Inc.
CompanyName : SwankSoft Technologies, Inc.
FileDescription : HK PopUp Killer
InternalName : hkPopupKiller
OriginalFilename : hkPopupKiller.exe
ProductName : HK PopUp Killer
Created on : 1/18/2003 8:50:43 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 10/10/2003 7:13:44 AM
#:29 [dlg.exe]
FilePath : C:\Program Files\Digital Line Detect\
ThreadCreationTime : 4-24-2004 12:17:02 PM
BasePriority : Normal
FileSize : 24 KB
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
Copyright : Copyright
CompanyName : BVRP Software
FileDescription : Digital Line Detection
InternalName : TestLine
OriginalFilename : TestLine.exe
ProductName : BVRP Software TestLine
Created on : 1/6/2004 1:25:05 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 6/20/2003 9:43:00 AM
#:30 [mpfagent.exe]
FilePath : C:\PROGRA~1\McAfee.com\PERSON~1\
ThreadCreationTime : 4-24-2004 12:17:02 PM
BasePriority : Normal
FileSize : 500 KB
FileVersion : 4.1.0.1
ProductVersion : 4.1.0.1
Copyright : Copyright
CompanyName : McAfee Security
FileDescription : McAfee Personal Firewall Agent Interface
InternalName : MpfAgent
OriginalFilename : MPFAGENT.EXE
ProductName : McAfee Personal Firewall (MPF)
Created on : 1/31/2004 3:25:48 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 9/2/2003 7:00:00 PM
#:31 [sgmain.exe]
FilePath : C:\Program Files\SpywareGuard\
ThreadCreationTime : 4-24-2004 12:17:02 PM
BasePriority : Normal
FileSize : 352 KB
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
Copyright : Copyright © 2002-2003 Javacool Software LLC
FileDescription : SpywareGuard
InternalName : sgmain
OriginalFilename : sgmain.exe
ProductName : SpywareGuard
Created on : 8/29/2003 11:05:35 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 8/29/2003 11:05:35 PM
#:32 [sgbhp.exe]
FilePath : C:\Program Files\SpywareGuard\
ThreadCreationTime : 4-24-2004 12:17:03 PM
BasePriority : Normal
FileSize : 228 KB
FileVersion : 2.02.0001
ProductVersion : 2.02.0001
Copyright : Copyright © 2002-2003 Javacool Software LLC.
FileDescription : SG Browser Hijacking Protection
InternalName : sgbhp
OriginalFilename : sgbhp.exe
ProductName : SG Browser Hijacking Protection
Created on : 8/29/2003 3:14:56 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 8/29/2003 3:14:56 PM
#:33 [acsd.exe]
FilePath : C:\PROGRA~1\COMMON~1\AOL\ACS\
ThreadCreationTime : 4-24-2004 12:17:05 PM
BasePriority : Normal
FileSize : 1344 KB
FileVersion : 1,0,17,5
ProductVersion : 1,0,17,5
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : AOL Connectivity Service
InternalName : acsd
OriginalFilename : acsd.exe
ProductName : AOL Connectivity Service
Created on : 1/6/2004 1:30:02 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 8/6/2003 10:58:26 PM
#:34 [mpfservice.exe]
FilePath : C:\PROGRA~1\McAfee.com\PERSON~1\
ThreadCreationTime : 4-24-2004 12:17:05 PM
BasePriority : Normal
FileSize : 492 KB
FileVersion : 4.1.0.1
ProductVersion : 4.1.0.1
Copyright : Copyright
CompanyName : McAfee Corporation
FileDescription : McAfee Personal Firewall Service
InternalName : MPFService
OriginalFilename : MpfService.exe
ProductName : McAfee Personal Firewall
Created on : 1/31/2004 3:25:48 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 9/2/2003 7:00:00 PM
#:35 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-24-2004 12:17:08 PM
BasePriority : Normal
FileSize : 12 KB
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
OriginalFilename : svchost.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:04:27 AM
Last modified : 8/29/2002 11:00:00 AM
#:36 [wanmpsvc.exe]
FilePath : C:\WINDOWS\
ThreadCreationTime : 4-24-2004 12:17:08 PM
BasePriority : Normal
FileSize : 64 KB
FileVersion : 7, 0, 0, 2
ProductVersion : 7, 0, 0, 2
Copyright : Copyright
CompanyName : America Online, Inc.
FileDescription : Wan Miniport (ATW) Service
InternalName : WanMPSvc
OriginalFilename : WanMPSvc.exe
ProductName : America Online
Created on : 1/6/2004 1:30:12 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 1/10/2003 11:13:04 PM
#:37 [ipodservice.exe]
FilePath : C:\Program Files\iPod\bin\
ThreadCreationTime : 4-24-2004 12:17:12 PM
BasePriority : Normal
FileSize : 396 KB
FileVersion : 1.0.0.85
ProductVersion : 2.0.1?0
Copyright : Copyright 2002 Apple Computer, Inc
CompanyName : Apple Computer, Inc
FileDescription : iPodService Module
InternalName : iPodService
OriginalFilename : iPodService.EXE
ProductName : iPodService Module
Created on : 6/15/2003 12:54:46 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 6/15/2003 12:54:46 PM
#:38 [wuauclt.exe]
FilePath : C:\WINDOWS\System32\
ThreadCreationTime : 4-24-2004 12:18:19 PM
BasePriority : Normal
FileSize : 145 KB
FileVersion : 5.4.3790.20 built by: lab04_n
ProductVersion : 5.4.3790.20
CompanyName : Microsoft Corporation
FileDescription : Windows Update AutoUpdate Client
InternalName : wuauclt.exe
OriginalFilename : wuauclt.exe
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 1/31/2004 5:40:14 AM
#:39 [winword.exe]
FilePath : C:\Program Files\Microsoft Office\Office10\
ThreadCreationTime : 4-24-2004 12:22:14 PM
BasePriority : Normal
FileSize : 10338 KB
FileVersion : 10.0.4030
ProductVersion : 10.0.4030
Copyright : Copyright
CompanyName : Microsoft Corporation
FileDescription : Microsoft Word
InternalName : WinWord
OriginalFilename : WinWord.exe
ProductName : Microsoft Office XP
Created on : 5/3/2002 9:07:40 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 5/3/2002 9:07:40 PM
#:40 [msworks.exe]
FilePath : C:\Program Files\Microsoft Works\
ThreadCreationTime : 4-24-2004 12:22:17 PM
BasePriority : Normal
FileSize : 92 KB
FileVersion : 7.02.0710.1
ProductVersion : 7.02.0710.1
Copyright : Copyright
CompanyName : Microsoft
FileDescription : Microsoft
InternalName : MSWORKS
OriginalFilename : MSWorks.exe
ProductName : Microsoft
Created on : 7/10/2002 4:04:26 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 7/10/2002 4:04:26 PM
#:41 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 4-24-2004 12:27:10 PM
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:17:14 AM
Last modified : 8/29/2002 11:00:00 AM
#:42 [iexplore.exe]
FilePath : C:\Program Files\Internet Explorer\
ThreadCreationTime : 4-24-2004 12:28:34 PM
BasePriority : Normal
FileSize : 89 KB
FileVersion : 6.00.2800.1106 (xpsp1.020828-1920)
ProductVersion : 6.00.2800.1106
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
OriginalFilename : IEXPLORE.EXE
ProductName : Microsoft
Created on : 8/29/2002 11:00:00 AM
Last accessed : 4/25/2004 12:17:14 AM
Last modified : 8/29/2002 11:00:00 AM
#:43 [mmjb.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 4-24-2004 12:32:32 PM
BasePriority : Normal
FileSize : 2564 KB
FileVersion : 8.20.0107
ProductVersion : 8.20.0107
Copyright : Copyright
CompanyName : MUSICMATCH, Inc.
FileDescription : MUSICMATCH Jukebox
InternalName : mmjb
OriginalFilename : mmjb.EXE
ProductName : MUSICMATCH Jukebox
Created on : 1/10/2004 6:02:28 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 1/26/2004 3:46:48 PM
#:44 [mmdiag.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 4-24-2004 12:32:33 PM
BasePriority : Normal
FileSize : 84 KB
FileVersion : 8.20.0107
ProductVersion : 8.20.0107
Copyright : Copyright
CompanyName : MUSICMATCH, Inc.
FileDescription : Logging and tracing manager
InternalName : MMTraceExe
OriginalFilename : MMTraceExe.EXE
ProductName : MUSICMATCH JUKEBOX
Created on : 1/10/2004 6:02:29 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 1/26/2004 3:46:50 PM
#:45 [mm_director.exe]
FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
ThreadCreationTime : 4-24-2004 12:32:35 PM
BasePriority : Normal
FileSize : 204 KB
FileVersion : 8.20.0107
ProductVersion : 8.20.0107
Copyright : Copyright
CompanyName : MUSICMATCH, Inc.
FileDescription : mm_director exe
InternalName : mm_director
OriginalFilename : mm_director.exe
ProductName : MUSICMATCH JUKEBOX
Created on : 1/6/2004 1:33:30 AM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 2/27/2004 12:20:17 AM
#:46 [wzqkpick.exe]
FilePath : C:\PROGRA~1\WINZIP\
ThreadCreationTime : 4-24-2004 12:45:18 PM
BasePriority : Normal
FileSize : 116 KB
FileVersion : 1.0 (32-bit)
ProductVersion : 9.0 (6028)
Copyright : Copyright © WinZip Computing, Inc. 1991-2004 - All Rights Reserved
CompanyName : WinZip Computing, Inc.
FileDescription : WinZip Executable
InternalName : WZQKPICK.EXE
OriginalFilename : WZQKPICK.EXE
ProductName : WinZip
Created on : 4/24/2004 12:43:52 PM
Last accessed : 4/25/2004 12:22:23 AM
Last modified : 2/11/2004 1:00:00 PM
#:47 [ad-aware.exe]
FilePath : C:\Program Files\Lavasoft\Ad-aware 6\
ThreadCreationTime : 4-25-2004 12:21:33 AM
BasePriority : Normal
FileSize : 668 KB
FileVersion : 6.0.1.181
ProductVersion : 6.0.0.0
Copyright : Copyright
CompanyName : Lavasoft Sweden
FileDescription : Ad-aware 6 core application
InternalName : Ad-aware.exe
OriginalFilename : Ad-aware.exe
ProductName : Lavasoft Ad-aware Plus
Created on : 3/20/2004 4:56:39 PM
Last accessed : 4/25/2004 12:21:33 AM
Last modified : 7/13/2003 3:00:20 AM
Memory scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Started deep registry scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Deep registry scan result :
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Deep scanning and examining files (C:)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Disk scan result for C:\
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
New objects : 0
Objects found so far: 0
Scanning Hosts file(C:\WINDOWS\System32\drivers\etc\hosts)
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Hosts file scan result:
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
1 entries scanned.
New objects :0
Objects found so far: 0
8:35:14 PM Scan complete
Summary of this scan
ŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻŻ
Total scanning time :00:12:51:734
Objects scanned :178323
Objects identified :0
Objects ignored :0
New objects :0
******************
4. I already had CWShredder, and I ran it per your instructions :thumb: . The log is below:
Done!
Removed from your system:
- CWS.Msconfig
Windows XP (5.01.2600 SP1)
CWShredder v1.56.2
Written by Merijn - merijn@spywareinfo.com
For any additional help with this program or removing CWS, visit:
http://forums.spywareinfo.com/For information and documentation on the Coolwebsearch
trojan and its variants, visit:
http://www.spywareinfo.com/~merijn/cwschronicles.htmlFor donations to help support CWShredder, visit:
http://www.spywareinfo.com/~merijn/donate.html*****************
5. My search for "c:\windows\start.chm" and "c:\windows\start.html" didn't turn anything up.
*****************
6. I couldn't access the page you told me to (http://http://tools.zerosrealm.com/downloads/pv.zip). I kept getting a message that the page couldn't be displayed.
*****************
7. I'll change my passwords and run the online AV scans your suggested. McAfee VirusScan started giving me problems a while ago, and their support people told me to uninstall and then reinstall. I was able to uninstall, but I kept crashing on reinstall, so it is not up and running as of now (as an aside, everyone on this board is 100 times more helpful than anyone I talked to at McAfee

). My problems with the McAfee programs started (shortly) after the keqeek32 problems arose, so VirusScan was operating at the time of infection.
However, my McAfee firewall tells me that "keqeek32.exe has been blocked from access to the internet and cannot exchange date with any computer." Maybe this means that the trojan is not able to transmit any passwords back to the hacker?
******************
8. One last thing--I ran a search and found that that "msrexe" is still in some of my folders. Should this be the case?
Thanks again for all of your help for what has turned into a much bigger problem than I initially thought!!