Hi there!
On a friend's computer, who is a novice, this is what NOD32 has prompted during a virus scan:-
probably a variant of Win32/PSW.OnLineGames.NFY trojan found in operating memory. The file can be deleted. It is strongly recommended that you back up any crucial data before you proceed. No action can be taken while the file is in memory. Click "Leave" to continue and subsequently run the cleaning of all local disks. System memory infection originated from file C:\WINDOWS\system32\kb1ss1p.dll.
NOD32 cannot delete/fix this infection? Here is the event log:-
NOD 32 event log
Time Module Event User
10/10/2007 18:01:33 NOD32 An alert has been generated. See the on-demand scanner Log for details. CAT\Catherine
09/10/2007 21:00:43 Kernel The virus signature database has been successfully updated to version 2581 (20071009).
09/10/2007 11:26:16 Kernel The virus signature database has been successfully updated to version 2579 (20071009).
08/10/2007 23:00:51 Update Function: gethostbyname, parameters: , return value: 11004
08/10/2007 23:00:51 Update Update attempt failed (Server connection failure.)
08/10/2007 19:36:19 Update Function: gethostbyname, parameters: , return value: 11004
08/10/2007 19:36:19 Update Update attempt failed (Server connection failure.)
08/10/2007 18:35:19 Update Function: gethostbyname, parameters: , return value: 11004
08/10/2007 18:35:19 Update Update attempt failed (Server connection failure.)
08/10/2007 14:47:54 Update Function: gethostbyname, parameters: , return value: 11004
08/10/2007 14:47:54 Update Update attempt failed (Server connection failure.)
08/10/2007 10:00:05 Kernel The virus signature database has been successfully updated to version 2577 (20071008).
07/10/2007 12:16:25 Kernel The virus signature database has been successfully updated to version 2576 (20071007).
06/10/2007 11:53:05 Kernel The virus signature database has been successfully updated to version 2575 (20071006).
05/10/2007 15:58:24 Kernel The virus signature database has been successfully updated to version 2574 (20071005).
04/10/2007 18:58:52 Kernel The virus signature database has been successfully updated to version 2572 (20071004).
04/10/2007 16:57:29 Kernel The virus signature database has been successfully updated to version 2571 (20071004).
03/10/2007 15:47:19 Kernel The virus signature database has been successfully updated to version 2569 (20071003).
02/10/2007 23:24:55 Kernel The virus signature database has been successfully updated to version 2567 (20071002).
02/10/2007 19:41:11 Update Update attempt failed (Server connection failure)
02/10/2007 18:43:28 Kernel The virus signature database has been successfully updated to version 2566 (20071002).
02/10/2007 17:41:11 Update Update attempt failed (Server connection failure)
02/10/2007 15:52:40 Update Update attempt failed (Server connection failure)
02/10/2007 13:31:17 Kernel The virus signature database has been successfully updated to version 2565 (20071002).
01/10/2007 18:58:25 Kernel The virus signature database has been successfully updated to version 2563 (20071001).
30/09/2007 13:37:43 Kernel The virus signature database has been successfully updated to version 2560 (20070930).
29/09/2007 21:40:41 Update Function: gethostbyname, parameters: , return value: 11004
29/09/2007 21:40:41 Update Update attempt failed (Server connection failure.)
29/09/2007 20:35:35 Update Function: gethostbyname, parameters: , return value: 11004
29/09/2007 20:35:35 Update Update attempt failed (Server connection failure.)
25/09/2007 18:00:05 Kernel The virus signature database has been successfully updated to version 2549 (20070925).
24/09/2007 19:24:53 Kernel The virus signature database has been successfully updated to version 2547 (20070924).
23/09/2007 13:40:58 Kernel The virus signature database has been successfully updated to version 2545 (20070923).
21/09/2007 20:08:29 Kernel The virus signature database has been successfully updated to version 2544 (20070921).
04/01/1999 12:35:37 Kernel The virus signature database has been successfully updated to version 2543 (20070921).
03/01/1999 16:48:58 Kernel The virus signature database has been successfully updated to version 2541 (20070920).
02/01/1999 15:35:49 Kernel The virus signature database has been successfully updated to version 2540 (20070919).
17/11/2007 22:47:17 Kernel The virus signature database has been successfully updated to version 2535 (20070917).
17/11/2007 12:21:59 Kernel The virus signature database has been successfully updated to version 2534 (20070917).
16/11/2007 12:14:19 Kernel The virus signature database has been successfully updated to version 2532 (20070916).
15/11/2007 13:58:28 Kernel The virus signature database has been successfully updated to version 2531 (20070915).
14/11/2007 13:24:03 Kernel The virus signature database has been successfully updated to version 2530 (20070914).
14/11/2007 10:13:36 Update Function: gethostbyname, parameters: , return value: 11004
14/11/2007 10:13:35 Update Update attempt failed (Server connection failure.)
14/11/2007 00:48:02 Kernel The virus signature database has been successfully updated to version 2529 (20070913).
13/11/2007 21:46:40 Update Function: gethostbyname, parameters: , return value: 11004
13/11/2007 21:46:40 Update Update attempt failed (Server connection failure.)
13/11/2007 16:47:56 Kernel The virus signature database has been successfully updated to version 2528 (20070913).
12/11/2007 23:20:50 Kernel The virus signature database has been successfully updated to version 2525 (20070912).
11/11/2007 22:23:41 Kernel The virus signature database has been successfully updated to version 2522 (20070911).
11/11/2007 18:24:04 Kernel The virus signature database has been successfully updated to version 2521 (20070911).
threat log
Time Module Object Name Threat Action User Information
10/10/2007 17:42:40 Kernel file C:\WINDOWS\system32\kb1ss1p.dll probably a variant of Win32/PSW.OnLineGames.NFY trojan
09/10/2007 11:27:33 Kernel file C:\WINDOWS\system32\kb1ss1p.dll probably a variant of Win32/PSW.OnLineGames.NFY trojan
09/10/2007 11:27:18 Kernel file c:\windows\system32\kb1ss1p.dll probably a variant of Win32/PSW.OnLineGames.NFY trojan
30/09/2007 17:43:58 IMON archive http://launch.gamespyarcade.com/softwar ... launch.cab Win32/TrojanDownloader.SpyGame.A trojan Connection terminated CAT\Sean
14/11/2007 00:47:20 AMON file C:\Documents and Settings\Catherine\Local Settings\Temporary Internet Files\Content.IE5\OPEV8X2R\s_sinstallerandtoolbar3_en-gb[1].exe a variant of Win32/Adware.Comet application quarantined - deleted CAT\Catherine Event occurred on a new file created by the application: C:\Program Files\Internet Explorer\iexplore.exe. The file was moved to quarantine. You may close this window.
14/11/2007 00:44:53 IMON self-extracting archive http://dm.screensavers.com/dm/installer ... _en-gb.exe a variant of Win32/Adware.Comet application CAT\Catherine
...and I understand at least one of the logins homepages on this same computer has been hijacked:-
Logfile of HijackThis v1.99.1
Scan saved at 15:30:00, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis\HijackThis.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [GLDStart] C:\Program Files\GLDirect\gldirect.exe -filterstart
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZI ... b56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
As usual, most grateful for any instructions on how to fix!
Best regards

