thank you very much indeed, Calamity Jane -
i tried to upload that file you asked for, but i'm afraid it isn't the one you're interested in: there's no lsass in sight when i check the WINNT folder (except if i look inside other folders: there's "lsass.exe" in that "RollUpPackUninstall" folder, and LSASS.exe in the system32 folder). i see [below] that it's still in the Highjack This log, so i reckon it's hiding from me when i search for it? if there's something i can do to coax it into view so that i can upload it for you, i'll gladly and gratefully try again ...
meanwhile, another friend decided to try to help me out here; he uninstalled all the Norton stuff, installed AVast instead; and also dowloaded a different SmitFraudFix and ran that in safe mode. i can't find a log for what SmitFraudFix did, but here are my latest Highjack This logs, and the logs that Avast generated last night and this morning (it's in Polish, sorry! but i've translated what i hope are the significant bits).
the computer seems to be running okay for a while after i start it, but keeps getting painfully slow; i *am* able to get/stay on line, but every time i do Avast reports/quarantines four trojans in a row.
many thanks for all your help and advice ...
~~~~~~~~~~~~~~~~~~~
Logfile of HijackThis v1.99.1
Scan saved at 9:43:47 AM, on 2006-10-24
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINNT\csrss.exe
C:\WINNT\lsass.exe
c:\winnt\system32\microsoft\user\FireDaemon.EXE
c:\winnt\system32\microsoft\user\dll39.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\slserv.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINNT\system32\sistray.EXE
C:\WINNT\system32\khooker.exe
C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Wanadoo\taskbaricon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINNT\system32\internat.exe
C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
C:\Program Files\Microsoft Office\Office\OSA.EXE
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\unzipped\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = L1cza
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O4 - HKLM\..\Run: [SiS Tray] C:\WINNT\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINNT\system32\khooker.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\Program Files\Wanadoo\taskbaricon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [internat.exe] internat.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Microsoft Office Shortcut Bar.lnk = C:\Program Files\Microsoft Office\Office\MSOFFICE.EXE
O4 - Global Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINNT\system32\SHDOCVW.DLL
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1160640790354O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1160657231421O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/s...nfo/webscan.cabO17 - HKLM\System\CS2\Services\Tcpip\..\{7B0406B9-DC57-4A74-BF16-DD91EC23D6CE}: NameServer = 194.204.152.34 217.98.63.164
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Us3uga administracyjna Mened?era dysków logicznych (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Generic Host Process for Win32 Service - Unknown owner - C:\WINNT\csrss.exe
O23 - Service: LSA Shel (Export Version) - Unknown owner - C:\WINNT\lsass.exe
O23 - Service: FireDaemon Service: MSVC9 (MSVC9) - Unknown owner - c:\winnt\system32\microsoft\user\FireDaemon.EXE
O23 - Service: FireDaemon Service: QOS (QOS) - Unknown owner - c:\winnt\system32\microsoft\user\FireDaemon.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINNT\SYSTEM32\slserv.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Avast logs:
* Raport avast!
* Ten plik jest generowany automatycznie
*
* Użyto zadania 'Osłona rezydentna'
* Uruchomiono 23 październik 2006 19:09:14 =
october 23rd 2006 19:09:14* VPS: 0639-1, 2006-09-25
*
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
c:\winnt\system32\microsoft\user\dll32.exe [L] Win32:Iroffer-011 [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\wen6j4d5.exe [L] Win32:Dialer-gen13 [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\Documents and Settings\Default User\Ustawienia lokalne\Temporary Internet Files\Content.IE5\T3P5FGN6\Browser[1].exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\j1ho6.exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantined
*~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
next report:* Raport avast!
* Ten plik jest generowany automatycznie
*
* Użyto zadania 'Osłona rezydentna'
* Uruchomiono 23 październik 2006 21:46:44 =
october 23rd 21:46:44* VPS: 0643-1, 2006-10-23
*
C:\Documents and Settings\Default User\Ustawienia lokalne\Temporary Internet Files\Content.IE5\4E9PT612\Browser[1].exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\j1ho6.exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\Documents and Settings\Default User\Ustawienia lokalne\Temporary Internet Files\Content.IE5\T3P5FGN6\adult1[1].exe [L] Win32:Dialer-gen13 [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantined
C:\wen6j4d5.exe [L] Win32:Dialer-gen13 [Trj] (0)Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantined~~~~~~~~~~~~~~~~~~~~~~~~~~
t
his morning: * Raport avast!
* Ten plik jest generowany automatycznie
*
* Użyto zadania 'Osłona rezydentna'
* Uruchomiono 24 październik 2006 07:14:52 =
october 24th 07:14:52* VPS: 0643-1, 2006-10-23
*
C:\Documents and Settings\Default User\Ustawienia lokalne\Temporary Internet Files\Content.IE5\LVQCP2IY\Browser[1].exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\Documents and Settings\Default User\Ustawienia lokalne\Temporary Internet Files\Content.IE5\LVQCP2IY\adult1[1].exe [L] Win32:Dialer-gen13 [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\j1ho6.exe [L] Win32:Dialer-BZ [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantinedC:\wen6j4d5.exe [L] Win32:Dialer-gen13 [Trj] (0)
Plik został przeniesiony do kwarantanny z powodzeniem... =
the file was successfully quarantined