Spyware and Viruses?
#31 Guest_poporacer_*
Posted 02 May 2006 - 08:23 AM
Register to Remove
#32
Posted 02 May 2006 - 02:08 PM
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
- The program will launch and then start to download the latest definition files.
- Once the scanner is installed and the definitions downloaded, click Next.
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Extended (If available otherwise Standard)
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Scan using the following Anti-Virus database:
- Click OK
- Now under select a target to scan select My Computer
- The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
- Copy and paste that information in your next post as well as a bew hijackthis log please.
#33 Guest_poporacer_*
Posted 05 May 2006 - 08:49 AM
#34
Posted 05 May 2006 - 09:08 PM
http://siri.urz.free...mitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.
______________________________
Please download the trial version of Ewido anti-malware 3.5 from here:
http://www.ewido.net/en/download/
- Install Ewido anti-malware.
- When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
- When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
- The program will prompt you to update. Click the Ok button.
- The program will now go to the main screen.
- On the left-hand side of the main screen click the Update Button.
- Click on Start.
Once finished updating, close Ewido.
If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter
This program will scan large amounts of files on your computer for known patterns so please be patient while it works. When it is done, the results of the scan will be displayed and it will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
IMPORTANT: Do NOT run any other options until you are asked to do so!
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Running the Clean
Warning: running option #2 on a non infected computer will remove your Desktop background.
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.
Reboot your computer in Safe Mode.
- If the computer is running, shut down Windows, and then turn off the power.
- Wait 30 seconds, and then turn the computer on.
- Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
- Ensure that the Safe Mode option is selected.
- Press Enter. The computer then begins to start in Safe mode.
- Login on your usual account.
Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.
A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.
The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________
Clean out your Temporary Internet files. Proceed like this:
- Quit Internet Explorer and quit any instances of Windows Explorer.
- Click Start, click Control Panel, and then double-click Internet Options.
- On the General tab, click Delete Files under Temporary Internet Files.
- In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
- On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
- Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
- Click OK.
Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________
Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
- Click on Scanner
- Click on Settings
- Under How to scan all boxes should be checked
- Under Unwanted Software all boxes should be checked
- Under What to scan select Scan every file
- Click on Ok
- Click on Complete System Scan to start the scan process.
- Let the program scan the machine.
Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
- Click Save Report button
- Save the report to your Desktop
______________________________
Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer Yes to the question "Restore Trusted Zone ?" by typing
Y and hit Enter.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________
Please post:
- c:\rapport.txt
- Ewido log
- A new HijackThis log
#35 Guest_poporacer_*
Posted 08 May 2006 - 11:04 AM
#36 Guest_poporacer_*
Posted 08 May 2006 - 11:22 AM
Logfile of HijackThis v1.99.1
Scan saved at 9:55:50 AM, on 5/8/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\FSGK32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fssm32.exe
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\F-Secure Internet Security\Common\FAMEH32.EXE
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsqh.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsrw.exe
C:\Program Files\F-Secure Internet Security\FSPC\fspc.exe
C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure Internet Security\Anti-Virus\fsav32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE
C:\Program Files\Cookie Washer\aolwasher.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
C:\PROGRA~1\F-SECU~1\ANTI-S~1\fsaw.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLHOS~1.EXE
C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
C:\Program Files\F-Secure Internet Security\FSGUI\fsguidll.exe
C:\Program Files\America Online 9.0a\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLServiceHost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://store.presari...&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=1c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
R3 - Default URLSearchHook is missing
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brazeal\Application Data\Mozilla\Profiles\default\alhwq5n1.slt\prefs.js)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107146022\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure Internet Security\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure Internet Security\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\F-Secure Internet Security\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Program Files\F-Secure Internet Security\FSGUI\ispnews.exe"
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Brazeal"
O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: F-Secure 2006.lnk = C:\Program Files\F-Secure Internet Security\backweb\4476822\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure Internet Security\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Web Filter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\F-Secure Internet Security\FSPC\fspcmsie.dll
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure Internet Security\Anti-Spyware\ieshield.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra button: Advisor - {0F2E637F-E3AF-49BB-8BCF-2CFAEDF862EF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for ¸ĉu
: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol....oach_core_1.cab
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: F-Secure 2006 (BackWeb Plug-in - 4476822) - F-Secure Internet Security 2005 - C:\PROGRA~1\F-SECU~1\backweb\4476822\Program\SERVIC~1.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure Internet Security\backweb\4476822\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\FSPC\fshttps\fshttps.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
#37
Posted 09 May 2006 - 09:30 PM
STEP 1.
======
SpySweeper
Please download http://www.webroot.c...ode=af1&rc=3597
(It's a 2 week trial):
- Click the Free Trial link under to "SpySweeper" to download the program.
- Install it.
- Once the program is installed, it will open.
- It will prompt you to update to the latest definitions, click Yes.
- Once the definitions are installed, click Sweep Now on the left side.
- Click the Start button.
- When it's done scanning, click the Next button.
- Make sure everything has a check next to it, then click the Next button.
- It will remove all of the items found.
- Click Session Log in the upper right corner, copy everything in that window.
- Click the Summary tab and click Finish.
- Paste the contents of the session log you copied into your next reply.
======
Download Ewido
- Download and install Ewido Security Suite It is a free trial version of the program.
- Install ewido security suite
- Launch ewido, there should be an icon on your desktop double-click it.
- The program will now go to the main screen
======
Update Ewido
You will need to update ewido to the latest definition files.
- On the left hand side of the main screen click update
- Then click on Start Update
If you are having problems with the updater, you can use Ewido manual updates
STEP 4.
======
Ewido Scan
Once the updates are installed do the following:
- Click on scanner
- Click on Complete System Scan and the scan will begin.
- NOTE: During some scans with ewido it is finding cases of false positives.**
o You will need to step through the process of cleaning files one-by-one.
o If ewido detects a file you KNOW to be legitimate, select none as the action.
o DO NOT select "Perform action on all infections"
o If you are unsure of any entry found select none for now. - Once the scan has completed, there will be a button located on the bottom of the screen named Save report
- Click Save report.
- Save the report .txt file to your desktop.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")
STEP 5.
======
CWShredder
Please download and run CWShredder
Make sure that all browser windows are closed with the exception of Cwshredder and choose FIX.
STEP 6.
======
Please do an onlione scan here http://housecall.trendmicro.com/ and allow it to clean/remove what it finds.
Please post the results from SpySweeper, ewido and a new hijackthis log.
#38 Guest_poporacer_*
Posted 15 May 2006 - 12:46 PM
********
6:44 PM: | Start of Session, Friday, May 12, 2006 |
6:44 PM: Spy Sweeper started
6:44 PM: Sweep initiated using definitions version 677
6:44 PM: Starting Memory Sweep
6:53 PM: Memory Sweep Complete, Elapsed Time: 00:08:44
6:53 PM: Starting Registry Sweep
6:54 PM: Found Trojan Horse: trojan-phisher-egold
6:54 PM: HKLM\system\currentcontrolset\services\docentd\ (12 subtraces) (ID = 933579)
6:54 PM: Found Adware: cws_tiny0
6:54 PM: HKCR\clsid\{9adc5b7c-f0fa-a733-e146-85ce8933dc68}\ (2 subtraces) (ID = 980881)
6:54 PM: HKLM\software\classes\clsid\{9adc5b7c-f0fa-a733-e146-85ce8933dc68}\ (2 subtraces) (ID = 980889)
6:54 PM: Registry Sweep Complete, Elapsed Time:00:01:19
6:54 PM: Starting Cookie Sweep
6:54 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
6:54 PM: Starting File Sweep
6:55 PM: win.ini.backup:ixqzel (ID = 200)
6:57 PM: Found Trojan Horse: trojan-backdoor-haxdoor
6:57 PM: 3928.tmp (ID = 192965)
7:21 PM: Found Trojan Horse: trojan-downloader-pr-corp
7:21 PM: 3208.tmp (ID = 188692)
7:40 PM: system.ini.backup:xbxng (ID = 204)
7:41 PM: Found Trojan Horse: trojan-backdoor-securemulti
7:41 PM: 3240.tmp (ID = 188688)
7:45 PM: 3200.tmp (ID = 192965)
7:45 PM: Found Trojan Horse: mspm-bot
7:45 PM: 2480.tmp (ID = 192909)
7:45 PM: 3600.tmp (ID = 188688)
7:55 PM: 3360.tmp (ID = 192909)
7:56 PM: 3532.tmp (ID = 188692)
8:00 PM: 3572.tmp (ID = 188692)
8:02 PM: Warning: Failed to open file "c:\windows\". The system cannot find the path specified
8:02 PM: Warning: Failed to open file "c:\windows\". The system cannot find the path specified
8:04 PM: 3248.tmp (ID = 192909)
8:05 PM: File Sweep Complete, Elapsed Time: 01:10:47
8:05 PM: Full Sweep has completed. Elapsed time 01:21:17
8:05 PM: Traces Found: 31
8:06 PM: Removal process initiated
8:06 PM: Quarantining All Traces: trojan-backdoor-haxdoor
8:07 PM: Quarantining All Traces: trojan-backdoor-securemulti
8:07 PM: Quarantining All Traces: trojan-downloader-pr-corp
8:07 PM: Quarantining All Traces: cws_tiny0
8:07 PM: Quarantining All Traces: mspm-bot
8:07 PM: Quarantining All Traces: trojan-phisher-egold
8:07 PM: Removal process completed. Elapsed time 00:00:33
********
8:29 AM: | Start of Session, Thursday, May 11, 2006 |
8:29 AM: Spy Sweeper started
8:29 AM: Sweep initiated using definitions version 556
8:30 AM: Starting Memory Sweep
8:37 AM: Memory Sweep Complete, Elapsed Time: 00:06:58
8:37 AM: Starting Registry Sweep
8:37 AM: Found Adware: 2020search
8:37 AM: HKLM\system\currentcontrolset\services\.net connection service\ (12 subtraces) (ID = 101924)
8:37 AM: Found Adware: coolwebsearch (cws)
8:37 AM: HKCR\clsid\{3ce36d52-d914-5ba5-c0e2-3f53ae992abb}\ (2 subtraces) (ID = 107209)
8:37 AM: HKCR\clsid\{4fc7118f-cec2-4822-4fa2-bd496c690a0c}\ (2 subtraces) (ID = 107248)
8:37 AM: HKCR\clsid\{75a46c7e-d7ab-55f3-8df2-d9a7ffd913e6}\ (2 subtraces) (ID = 107518)
8:37 AM: HKCR\clsid\{d02510a9-69a7-24d5-85da-d3ec8e911c73}\ (2 subtraces) (ID = 108130)
8:37 AM: HKCR\clsid\{f22b79fb-1d55-c94f-4938-eaa13a2fb4ed}\ (2 subtraces) (ID = 108311)
8:37 AM: HKCR\interface\{c19eb5b1-fc58-456e-8793-384532ed5970}\ (8 subtraces) (ID = 108398)
8:37 AM: HKLM\software\classes\clsid\{3ce36d52-d914-5ba5-c0e2-3f53ae992abb}\ (2 subtraces) (ID = 108597)
8:37 AM: HKLM\software\classes\clsid\{4fc7118f-cec2-4822-4fa2-bd496c690a0c}\ (2 subtraces) (ID = 108636)
8:37 AM: HKLM\software\classes\clsid\{75a46c7e-d7ab-55f3-8df2-d9a7ffd913e6}\ (2 subtraces) (ID = 108905)
8:37 AM: HKLM\software\classes\clsid\{d02510a9-69a7-24d5-85da-d3ec8e911c73}\ (2 subtraces) (ID = 109513)
8:37 AM: HKLM\software\classes\clsid\{f22b79fb-1d55-c94f-4938-eaa13a2fb4ed}\ (2 subtraces) (ID = 109692)
8:37 AM: HKLM\software\classes\interface\{c19eb5b1-fc58-456e-8793-384532ed5970}\ (8 subtraces) (ID = 109776)
8:37 AM: Found Adware: cws-aboutblank
8:37 AM: HKCR\clsid\{5af56848-9589-c8be-da68-602b3e69097e}\ (2 subtraces) (ID = 113034)
8:37 AM: HKCR\interface\{53b95210-7d77-11d2-9f81-00104b107c96}\ (8 subtraces) (ID = 114337)
8:37 AM: HKLM\software\classes\clsid\{5af56848-9589-c8be-da68-602b3e69097e}\ (2 subtraces) (ID = 114616)
8:37 AM: HKLM\software\classes\typelib\{53b95204-7d77-11d2-9f81-00104b107c96}\ (9 subtraces) (ID = 115914)
8:37 AM: HKCR\typelib\{53b95204-7d77-11d2-9f81-00104b107c96}\ (9 subtraces) (ID = 116773)
8:37 AM: Found Adware: cws_ns3
8:37 AM: HKCR\clsid\{0b58bef4-c0d5-53ba-4f75-d23e40367540}\ (2 subtraces) (ID = 117606)
8:37 AM: HKCR\clsid\{02d6ed78-680a-f6c9-b9ce-a9a1ba770720}\ (2 subtraces) (ID = 117641)
8:37 AM: HKCR\clsid\{02ffd786-624f-cc5b-7820-bcdee66d486f}\ (2 subtraces) (ID = 117642)
8:37 AM: HKCR\clsid\{2b32079d-a94d-be39-977b-b79962faa6cf}\ (2 subtraces) (ID = 117746)
8:37 AM: HKCR\clsid\{3a044fba-5def-1ecf-55e6-8a9de3722cec}\ (2 subtraces) (ID = 117780)
8:37 AM: HKCR\clsid\{3f15b481-32e2-fe85-96fa-a8976289b4fd}\ (4 subtraces) (ID = 117819)
8:37 AM: HKCR\clsid\{5f574346-a206-d78a-7149-4c709d5204a4}\ (2 subtraces) (ID = 117912)
8:37 AM: HKCR\clsid\{7a987646-f4b5-d9fc-cc46-e95a1713f3b5}\ (2 subtraces) (ID = 117962)
8:37 AM: HKCR\clsid\{7d070854-e058-6cf4-d6a2-c2d80e5b5124}\ (2 subtraces) (ID = 117978)
8:37 AM: HKCR\clsid\{9a711817-cadb-fd03-ebb1-4e2fc70601c2}\ (2 subtraces) (ID = 118039)
8:37 AM: HKCR\clsid\{46b118f7-a9c3-30b6-f02a-a8c72e1e4fd5}\ (2 subtraces) (ID = 118179)
8:37 AM: HKCR\clsid\{46c8c875-7053-566f-b7df-a8735884b10e}\ (2 subtraces) (ID = 118180)
8:37 AM: HKCR\clsid\{47b70b6f-a6b0-230a-43c3-9f9b5c710209}\ (2 subtraces) (ID = 118181)
8:37 AM: HKCR\clsid\{67d02480-710b-80d7-0624-27bb57b32cde}\ (2 subtraces) (ID = 118239)
8:37 AM: HKCR\clsid\{73a0fef4-c4ec-89f0-f3bc-fe7f59ad1dba}\ (2 subtraces) (ID = 118258)
8:37 AM: HKCR\clsid\{86b29a5f-cb91-3c3d-28a2-eda38c1f28a8}\ (2 subtraces) (ID = 118288)
8:37 AM: HKCR\clsid\{792e2c95-aebd-d9b8-e958-ad1bb5a3d9ba}\ (2 subtraces) (ID = 118431)
8:37 AM: HKCR\clsid\{3684b1d1-c737-aa3a-00b8-83fe7ff3c058}\ (2 subtraces) (ID = 118488)
8:37 AM: HKCR\clsid\{4095aaf5-bad2-a97d-d64c-566a52e35c2e}\ (2 subtraces) (ID = 118494)
8:37 AM: HKCR\clsid\{8007f30a-add5-7e61-d29c-8f166bc8a3dd}\ (2 subtraces) (ID = 118535)
8:37 AM: HKCR\clsid\{15213f20-4568-a265-3c5a-1f0b1f772ef8}\ (2 subtraces) (ID = 118567)
8:37 AM: HKCR\clsid\{64770a00-0c3b-bcec-d32d-83ee61896228}\ (2 subtraces) (ID = 118592)
8:37 AM: HKCR\clsid\{61682029-a490-5c49-d9fd-682fb2da97af}\ (2 subtraces) (ID = 118711)
8:37 AM: HKCR\clsid\{a97b64ca-35c4-dd86-2890-054ee94ce844}\ (2 subtraces) (ID = 118768)
8:37 AM: HKCR\clsid\{b36d5282-d413-f545-cf79-a6ce970cfebb}\ (4 subtraces) (ID = 118861)
8:37 AM: HKCR\clsid\{b1300934-5207-3933-066d-455dde935add}\ (2 subtraces) (ID = 118893)
8:37 AM: HKCR\clsid\{be5dcdbc-54d3-95ea-b258-2d53bd817431}\ (2 subtraces) (ID = 118926)
8:37 AM: HKCR\clsid\{c42cf26e-2b02-05de-7d7b-a16c5c2095bb}\ (2 subtraces) (ID = 118987)
8:37 AM: HKCR\clsid\{cc6a9dff-521f-7dd3-e624-b30c0b9ff83a}\ (2 subtraces) (ID = 119047)
8:37 AM: HKCR\clsid\{d6c7db36-c0ac-c91f-b408-61a55e5ab6c5}\ (6 subtraces) (ID = 119094)
8:37 AM: HKCR\clsid\{d7b5394e-d013-3545-35d0-45376236a8dc}\ (4 subtraces) (ID = 119095)
8:37 AM: HKCR\clsid\{d7347ce7-1ee8-8788-b631-57750cdd6bcb}\ (2 subtraces) (ID = 119131)
8:37 AM: HKCR\clsid\{e36a99d7-088f-a5e8-1ba4-87116d938d49}\ (2 subtraces) (ID = 119237)
8:37 AM: HKCR\clsid\{e5181bb3-b821-0d7b-d568-3766286d5460}\ (2 subtraces) (ID = 119265)
8:37 AM: HKCR\clsid\{e365460d-7563-2763-5e38-85f172854eac}\ (6 subtraces) (ID = 119270)
8:37 AM: HKCR\clsid\{f0d9b410-3c4f-707c-2e2d-529e64aa2118}\ (2 subtraces) (ID = 119339)
8:37 AM: HKCR\clsid\{f1b9da5c-979c-674e-bdc1-14b48e7fdf72}\ (2 subtraces) (ID = 119346)
8:37 AM: HKCR\clsid\{f2352fd0-b78a-fc66-ee98-5dfbf99e1f48}\ (2 subtraces) (ID = 119400)
8:37 AM: HKCR\clsid\{fa112fa2-b6c7-ce6a-de50-feaf22c15154}\ (2 subtraces) (ID = 119418)
8:37 AM: HKCR\clsid\{fb277f1b-89b6-a114-dd01-ec507a933f39}\ (2 subtraces) (ID = 119426)
8:37 AM: HKLM\software\classes\clsid\{0b58bef4-c0d5-53ba-4f75-d23e40367540}\ (2 subtraces) (ID = 119486)
8:37 AM: HKLM\software\classes\clsid\{02d6ed78-680a-f6c9-b9ce-a9a1ba770720}\ (2 subtraces) (ID = 119520)
8:37 AM: HKLM\software\classes\clsid\{02ffd786-624f-cc5b-7820-bcdee66d486f}\ (2 subtraces) (ID = 119521)
8:37 AM: HKLM\software\classes\clsid\{1fe935ff-db66-ac76-99d8-18ec1f0f013c}\ (2 subtraces) (ID = 119613)
8:37 AM: HKLM\software\classes\clsid\{2b32079d-a94d-be39-977b-b79962faa6cf}\ (2 subtraces) (ID = 119622)
8:37 AM: HKLM\software\classes\clsid\{3a044fba-5def-1ecf-55e6-8a9de3722cec}\ (2 subtraces) (ID = 119654)
8:37 AM: HKLM\software\classes\clsid\{3f15b481-32e2-fe85-96fa-a8976289b4fd}\ (4 subtraces) (ID = 119693)
8:37 AM: HKLM\software\classes\clsid\{5f574346-a206-d78a-7149-4c709d5204a4}\ (2 subtraces) (ID = 119787)
8:37 AM: HKLM\software\classes\clsid\{7a987646-f4b5-d9fc-cc46-e95a1713f3b5}\ (2 subtraces) (ID = 119836)
8:37 AM: HKLM\software\classes\clsid\{7d070854-e058-6cf4-d6a2-c2d80e5b5124}\ (2 subtraces) (ID = 119853)
8:37 AM: HKLM\software\classes\clsid\{9a711817-cadb-fd03-ebb1-4e2fc70601c2}\ (2 subtraces) (ID = 119913)
8:37 AM: HKLM\software\classes\clsid\{46b118f7-a9c3-30b6-f02a-a8c72e1e4fd5}\ (2 subtraces) (ID = 120037)
8:37 AM: HKLM\software\classes\clsid\{46c8c875-7053-566f-b7df-a8735884b10e}\ (2 subtraces) (ID = 120038)
8:37 AM: HKLM\software\classes\clsid\{47b70b6f-a6b0-230a-43c3-9f9b5c710209}\ (2 subtraces) (ID = 120039)
8:37 AM: HKLM\software\classes\clsid\{67d02480-710b-80d7-0624-27bb57b32cde}\ (2 subtraces) (ID = 120096)
8:37 AM: HKLM\software\classes\clsid\{73a0fef4-c4ec-89f0-f3bc-fe7f59ad1dba}\ (2 subtraces) (ID = 120115)
8:37 AM: HKLM\software\classes\clsid\{86b29a5f-cb91-3c3d-28a2-eda38c1f28a8}\ (2 subtraces) (ID = 120144)
8:37 AM: HKLM\software\classes\clsid\{338e88e9-d821-1c15-a00d-907ab980e988}\ (2 subtraces) (ID = 120215)
8:37 AM: HKLM\software\classes\clsid\{792e2c95-aebd-d9b8-e958-ad1bb5a3d9ba}\ (2 subtraces) (ID = 120279)
8:37 AM: HKLM\software\classes\clsid\{3684b1d1-c737-aa3a-00b8-83fe7ff3c058}\ (2 subtraces) (ID = 120335)
8:37 AM: HKLM\software\classes\clsid\{4095aaf5-bad2-a97d-d64c-566a52e35c2e}\ (2 subtraces) (ID = 120341)
8:37 AM: HKLM\software\classes\clsid\{8007f30a-add5-7e61-d29c-8f166bc8a3dd}\ (2 subtraces) (ID = 120382)
8:37 AM: HKLM\software\classes\clsid\{15213f20-4568-a265-3c5a-1f0b1f772ef8}\ (2 subtraces) (ID = 120414)
8:37 AM: HKLM\software\classes\clsid\{64770a00-0c3b-bcec-d32d-83ee61896228}\ (2 subtraces) (ID = 120439)
8:37 AM: HKLM\software\classes\clsid\{61682029-a490-5c49-d9fd-682fb2da97af}\ (2 subtraces) (ID = 120553)
8:37 AM: HKLM\software\classes\clsid\{a97b64ca-35c4-dd86-2890-054ee94ce844}\ (2 subtraces) (ID = 120607)
8:37 AM: HKLM\software\classes\clsid\{b36d5282-d413-f545-cf79-a6ce970cfebb}\ (4 subtraces) (ID = 120700)
8:37 AM: HKLM\software\classes\clsid\{b1300934-5207-3933-066d-455dde935add}\ (2 subtraces) (ID = 120731)
8:37 AM: HKLM\software\classes\clsid\{be5dcdbc-54d3-95ea-b258-2d53bd817431}\ (2 subtraces) (ID = 120763)
8:37 AM: HKLM\software\classes\clsid\{c42cf26e-2b02-05de-7d7b-a16c5c2095bb}\ (2 subtraces) (ID = 120824)
8:37 AM: HKLM\software\classes\clsid\{cc6a9dff-521f-7dd3-e624-b30c0b9ff83a}\ (2 subtraces) (ID = 120884)
8:37 AM: HKLM\software\classes\clsid\{d6c7db36-c0ac-c91f-b408-61a55e5ab6c5}\ (6 subtraces) (ID = 120930)
8:37 AM: HKLM\software\classes\clsid\{d7b5394e-d013-3545-35d0-45376236a8dc}\ (4 subtraces) (ID = 120931)
8:37 AM: HKLM\software\classes\clsid\{e36a99d7-088f-a5e8-1ba4-87116d938d49}\ (2 subtraces) (ID = 121071)
8:37 AM: HKLM\software\classes\clsid\{e5181bb3-b821-0d7b-d568-3766286d5460}\ (2 subtraces) (ID = 121098)
8:37 AM: HKLM\software\classes\clsid\{e365460d-7563-2763-5e38-85f172854eac}\ (6 subtraces) (ID = 121102)
8:37 AM: HKLM\software\classes\clsid\{f0d9b410-3c4f-707c-2e2d-529e64aa2118}\ (2 subtraces) (ID = 121169)
8:37 AM: HKLM\software\classes\clsid\{f1b9da5c-979c-674e-bdc1-14b48e7fdf72}\ (2 subtraces) (ID = 121176)
8:37 AM: HKLM\software\classes\clsid\{f2352fd0-b78a-fc66-ee98-5dfbf99e1f48}\ (2 subtraces) (ID = 121227)
8:37 AM: HKLM\software\classes\clsid\{fa112fa2-b6c7-ce6a-de50-feaf22c15154}\ (2 subtraces) (ID = 121244)
8:37 AM: HKLM\software\classes\clsid\{fb277f1b-89b6-a114-dd01-ec507a933f39}\ (2 subtraces) (ID = 121251)
8:37 AM: Found Adware: cws_tiny0
8:37 AM: HKCR\clsid\{5f4b11a7-c0a8-0b95-8741-481c8b0029e3}\ (2 subtraces) (ID = 123846)
8:37 AM: HKCR\clsid\{8a71c47b-9917-b588-625b-79254d40a325}\ (2 subtraces) (ID = 123858)
8:37 AM: HKCR\clsid\{9c060fc3-f4ce-894d-8eb7-fa3935ce5aa1}\ (2 subtraces) (ID = 123869)
8:37 AM: HKCR\clsid\{99b1e639-dca2-2c21-013f-def4b5729ca9}\ (4 subtraces) (ID = 123902)
8:37 AM: HKCR\clsid\{226ef23f-8451-8515-bc02-3d0252c01453}\ (2 subtraces) (ID = 123906)
8:37 AM: HKCR\clsid\{cd283bb0-5fea-f204-bc88-8c3ca240315d}\ (2 subtraces) (ID = 124001)
8:37 AM: HKCR\clsid\{ea8d7dfa-04bf-99e7-595c-535dc7f0efba}\ (2 subtraces) (ID = 124025)
8:37 AM: HKLM\software\classes\clsid\{5f4b11a7-c0a8-0b95-8741-481c8b0029e3}\ (2 subtraces) (ID = 124080)
8:37 AM: HKLM\software\classes\clsid\{8a71c47b-9917-b588-625b-79254d40a325}\ (2 subtraces) (ID = 124092)
8:37 AM: HKLM\software\classes\clsid\{9c060fc3-f4ce-894d-8eb7-fa3935ce5aa1}\ (2 subtraces) (ID = 124102)
8:37 AM: HKLM\software\classes\clsid\{99b1e639-dca2-2c21-013f-def4b5729ca9}\ (4 subtraces) (ID = 124134)
8:37 AM: HKLM\software\classes\clsid\{226ef23f-8451-8515-bc02-3d0252c01453}\ (2 subtraces) (ID = 124137)
8:37 AM: HKLM\software\classes\clsid\{cd283bb0-5fea-f204-bc88-8c3ca240315d}\ (2 subtraces) (ID = 124231)
8:38 AM: HKCR\clsid\{44cda69e-e88e-5adf-7958-9569d48ea263}\ (2 subtraces) (ID = 879732)
8:38 AM: HKLM\software\classes\clsid\{44cda69e-e88e-5adf-7958-9569d48ea263}\ (2 subtraces) (ID = 879801)
8:38 AM: HKU\WRSS_Profile_S-1-5-21-480437244-2214429306-939620716-500\software\microsoft\internet explorer\main\ || homeoldsp (ID = 115923)
8:38 AM: Registry Sweep Complete, Elapsed Time:00:01:05
8:38 AM: Starting Cookie Sweep
8:38 AM: Cookie Sweep Complete, Elapsed Time: 00:00:01
8:38 AM: Starting File Sweep
8:39 AM: Found Trojan Horse: trojan-downloader-vxiframe
8:39 AM: 1324.tmp (ID = 107123)
8:39 AM: xpsp1hfm.log:fjacv (ID = 56194)
8:39 AM: xpsp1hfm.log:vbuas (ID = 56194)
8:39 AM: q815021.log:ohlom (ID = 56194)
8:41 AM: santa fe stucco.bmp:vpozf (ID = 56194)
8:41 AM: kb828741.log:orzoh (ID = 56194)
8:41 AM: vminst.log:zukjl (ID = 56194)
8:41 AM: syminst.log:rsmjf (ID = 56718)
8:41 AM: q317326.log:eootr (ID = 56194)
8:41 AM: q317326.log:odwpu (ID = 56194)
8:41 AM: unvise32qt.exe:misqh (ID = 56322)
8:41 AM: Found Adware: tvmedia
8:41 AM: blue lace 16.bmp:rzakq (ID = 81628)
8:41 AM: 002655_.tmp:geaxv (ID = 56322)
8:41 AM: kb825119.log:dtgqu (ID = 56194)
8:41 AM: q311889.log:samzb (ID = 56603)
8:41 AM: kb842773.log:tzshy (ID = 56194)
8:41 AM: wecxg32.dll (ID = 54008)
8:41 AM: zxmsn.dll (ID = 54008)
8:42 AM: gupd.dll (ID = 54008)
8:42 AM: cidpoq32.dll (ID = 54008)
8:42 AM: icvbr.dll (ID = 54008)
8:42 AM: icqrt.dll (ID = 54187)
8:42 AM: cidft.dll (ID = 54008)
8:42 AM: sdfup.dll (ID = 54008)
8:42 AM: xcwer32.dll (ID = 54008)
8:42 AM: ieuninst.exe:aukuhu (ID = 55692)
8:42 AM: ieuninst.exe:hzhpwz (ID = 54093)
8:42 AM: icnfe.dll (ID = 54008)
8:42 AM: greenstone.bmp:cwpku (ID = 56194)
8:42 AM: q329115.log:cnssm (ID = 56194)
8:42 AM: q329834.log:objlq (ID = 56322)
8:44 AM: dtcinstall.log:nhprv (ID = 54863)
8:45 AM: q312368.log:nomki (ID = 56450)
8:49 AM: win.ini.backup:gevio (ID = 56451)
8:49 AM: win.ini.backup:xhdmo (ID = 56714)
8:49 AM: twain_32.dll:vexig (ID = 56718)
8:50 AM: perwin.ini:nmuci (ID = 56194)
8:52 AM: q329390.log:hrlsk (ID = 56194)
8:52 AM: status.mif:zmbmq (ID = 56194)
8:52 AM: oewablog.txt:lfiem (ID = 56194)
8:52 AM: vbaddin.ini:ybucw (ID = 56194)
8:53 AM: q329170.log:cmnry (ID = 56194)
8:53 AM: orun32.ini:ogloa (ID = 56194)
8:53 AM: {3564a736-4c6c-4806-bf06-373e8387cb8c}.dat:uhudp (ID = 56194)
8:53 AM: twain.dll:ecbjx (ID = 56194)
8:53 AM: kb840374.log:jbpch (ID = 56208)
8:54 AM: cdplayer.ini:xmhoe (ID = 56194)
8:54 AM: {6ae3c542-5bba-45cc-82c8-e6da3f99439c}.dat:nqdmm (ID = 56194)
8:55 AM: twunk_32.exe:xdlpr (ID = 56319)
8:55 AM: q315403.log:xxcui (ID = 56603)
8:56 AM: photosuite.ini:noyoy (ID = 56194)
8:56 AM: explorer.scf:vnyse (ID = 56194)
9:02 AM: oewablog.txt:mbsbc (ID = 56718)
9:02 AM: river sumida.bmp:kwjnu (ID = 56718)
9:04 AM: q810565.log:fzknmk (ID = 54093)
9:04 AM: 2484.tmp (ID = 107123)
9:07 AM: 524.tmp (ID = 107123)
9:08 AM: 3368.tmp (ID = 107123)
9:08 AM: 3480.tmp (ID = 107123)
9:08 AM: windows update.log:cwvvd (ID = 56718)
9:08 AM: windows update.log:yfovi (ID = 56208)
9:09 AM: q308678.log:ifwtu (ID = 54093)
9:09 AM: kb841873.log:fbinn (ID = 56322)
9:09 AM: kb841873.log:pqfkx (ID = 56322)
9:09 AM: comsetup.log:enbqh (ID = 56322)
9:09 AM: kb820291.log:luqmx (ID = 56322)
9:09 AM: {224cfcbf-d155-48ce-9923-21627b2ba31e}.dat:mphjs (ID = 56718)
9:09 AM: 4024.tmp (ID = 107123)
9:09 AM: Found Adware: security iguard
9:09 AM: chmhelp.chm (ID = 75238)
9:09 AM: nsreg.dat:kmyqi (ID = 56194)
9:10 AM: 2164.tmp (ID = 107123)
9:10 AM: windowsupdate.log:htlcu (ID = 56194)
9:10 AM: explorer.exe:gdytp (ID = 56322)
9:10 AM: Warning: Failed to open file "c:\windows\". The system cannot find the path specified
9:10 AM: Warning: Failed to open file "c:\windows\". The system cannot find the path specified
9:10 AM: msgsocm.log:aggqmo (ID = 54093)
9:10 AM: oeuninst.exe:rvmajw (ID = 57119)
9:11 AM: mtwcnl32.dll (ID = 54330)
9:11 AM: syncor.exe:dlykw (ID = 56194)
9:11 AM: apiry.dll:fbxqjp (ID = 56208)
9:11 AM: javayk32.dll:kvrys (ID = 56208)
9:11 AM: sysea32.dll:rijle (ID = 56208)
9:11 AM: appoq32.dll:tyvxxf (ID = 57119)
9:11 AM: javayk32.dll:ocuggb (ID = 57119)
9:11 AM: netvy.dll:pupglf (ID = 54093)
9:11 AM: netvy.dll:njrawb (ID = 54093)
9:11 AM: syninst.log:jbnba (ID = 56194)
9:11 AM: ntyd32.dll:wglgt (ID = 56194)
9:11 AM: Found Adware: cws_mailhook
9:11 AM: readme.txt (ID = 56128)
9:11 AM: Found Trojan Horse: mspm-bot
9:11 AM: ddr64.dll (ID = 150006)
9:12 AM: File Sweep Complete, Elapsed Time: 00:33:53
9:12 AM: Full Sweep has completed. Elapsed time 00:42:56
9:12 AM: Traces Found: 505
9:53 AM: Removal process initiated
9:53 AM: Quarantining All Traces: cws_ns3
10:04 AM: Quarantining All Traces: trojan-downloader-vxiframe
10:04 AM: Quarantining All Traces: cws-aboutblank
10:05 AM: Quarantining All Traces: 2020search
10:05 AM: Quarantining All Traces: coolwebsearch (cws)
10:08 AM: Quarantining All Traces: cws_mailhook
10:08 AM: Quarantining All Traces: cws_tiny0
10:10 AM: Quarantining All Traces: mspm-bot
10:10 AM: Quarantining All Traces: security iguard
10:10 AM: Quarantining All Traces: tvmedia
11:10 AM: Removal process completed. Elapsed time 01:16:34
6:42 PM: Your spyware definitions have been updated.
6:44 PM: | End of Session, Friday, May 12, 2006 |
********
9:31 PM: | Start of Session, Wednesday, May 10, 2006 |
9:31 PM: Spy Sweeper started
9:31 PM: Sweep initiated using definitions version 556
9:31 PM: Starting Memory Sweep
9:33 PM: Sweep Canceled
9:33 PM: Memory Sweep Complete, Elapsed Time: 00:01:32
9:33 PM: Traces Found: 0
********
9:23 PM: | Start of Session, Wednesday, May 10, 2006 |
9:23 PM: Spy Sweeper started
9:31 PM: | End of Session, Wednesday, May 10, 2006 |
The Ewido scan had the same results as before, it froze on a memory location and didn't finish. It didn't print a log.
CWShredder didn't find anything.
Housecall found a couple of things and I fixed them (I didn't write down what they were, I thought it would have a report.)
And here is my HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 11:33:35 AM, on 5/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLServiceHost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Cookie Washer\aolwasher.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\hjt\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://store.presari...&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=1c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brazeal\Application Data\Mozilla\Profiles\default\alhwq5n1.slt\prefs.js)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107146022\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Brazeal"
O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {0F2E637F-E3AF-49BB-8BCF-2CFAEDF862EF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for ¸ĉu
: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol....oach_core_1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.t...ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EFA4DDA-C9A7-4458-9F28-DD701D193851}: NameServer = 12.127.16.77,12.127.17.77
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thank you for your help!
#39 Guest_poporacer_*
Posted 18 May 2006 - 12:53 PM
#40
Posted 18 May 2006 - 08:18 PM
Register to Remove
#41 Guest_poporacer_*
Posted 19 May 2006 - 10:52 PM
Logfile of HijackThis v1.99.1
Scan saved at 9:45:30 PM, on 5/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Cookie Washer\aolwasher.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLHOS~1.EXE
C:\Program Files\America Online 9.0a\waol.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\Program Files\America Online 9.0a\shellmon.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hjt\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://store.presari...&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=1c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brazeal\Application Data\Mozilla\Profiles\default\alhwq5n1.slt\prefs.js)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107146022\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Brazeal"
O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0a\AOL.EXE" -b
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {0F2E637F-E3AF-49BB-8BCF-2CFAEDF862EF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for ¸ĉu
: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol....oach_core_1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.t...ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EFA4DDA-C9A7-4458-9F28-DD701D193851}: NameServer = 12.127.16.77,12.127.17.77
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
#42
Posted 20 May 2006 - 10:05 AM
Now we need to see if we need to restore some deleted files:Please check for the following files using the Windows Search Engine:
- control.exe
- rundll32.exe
- wmplayer.exe
- msconfig.exe
- notepad.exe
- shell.dll
- SDHelper.dll
Merijn's Files and following the instructions at that site to have them where they belong for your OS.
- If you are having any difficulty with Notepad, please go to Merijn's Files and choose 'Windows Files' from the menu on the left hand side of the page. Then choose 'Notepad' from the list and download it to C:\Windows and C:\Windows\System32
- Download the Hoster from here. Press "Restore Original Hosts" and press "OK". Exit Program. This will restore the original deleted Hosts file.
- This infection often deletes some system files that need to be replaced. The most frequent one it deletes is shell.dll in Win2K or XP. In XP there are two copies of this file, one in Windows (WINNT) and one in Windows\System32. It does not delete the one in Windows\System so it does not affect Win9x/ME. If you find it missing, please copy the shell.dll from c:\windows\system32\dllcache into both \Windows (WINNT) and Windows\System32 .
- The other system file which is most frequently deleted is control.exe. Please check to make sure that you have this file and it is the correct size. If not Please check for the existence of this file by going to to Merijn's Files (sdhelper) and examine where the file should be for your operating system. If the file is missing then download the appropriate file and place it in the proper place according to the information at this website. The control.exe is more often deleted in Win9x/ME.
- If you have Spybot S&D installed you will also need to replace one file. Go here: Merijn's Files (sdhelper) and download SDHelper.dll. Copy the file to the folder containing you Spybot S&D program (normally C:\Program Files\Spybot - Search & Destroy). Then click Start > Run > regsvr32 "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" and press the OK button
- Download Ccleaner to clean temp files from your computer.
- Double click on Ccleaner to install the program, with its default settings, selecting language and agreeing to the license agreement.
- Double click the CCleaner shortcut on the desktop to start the program.
- Click Options > Advanced and uncheck "Only delete files in Windows Temp folders older than 48 hours".
Step#3:Complete An Online AntiVirus Scan
Run an online antivirus scan at:
Trend Micro-Housecall Online AV
Reboot
Step#4:Find the Infected Files On Your Hard Drive
[list] - Navigate to C:\Windows
- look for files that were created at the approximate time and date as the infection occurred.
- look for those that end in exe, DAT and DLL and if found, right click on the file and check properties. Legitimate files should be copyrighted by Microsoft
- if you determine they are bad files, right click on them and choose delete
- Navigate to C:\Windows\System or C:\Windows\System32 (depending on the OS) and repeat each of the above steps to check for those ending in exe, DAT and/or DLL
- if the above files will not delete, then make a new folder on your desktop by right clicking on the desktop and choosing New > Folder. Name the folder CWS Files.
- Move the files from C:\Windows or C:\Windows\System or C:\Windows\system32
to the new folder CWS Files.
** In cases where many system files are missing you have no alternative but to have them insert their Windows OS disk and run sfc /scannow from the Run box if able or from Recovery Console if not able to get into windows[/b]
Step#6:Scan And Post a New HijackThis Log
1. Scan again with HijackThis
2. POST your log file using Add Reply to see what is left to fix.
#43 Guest_poporacer_*
Posted 22 May 2006 - 11:52 AM
Logfile of HijackThis v1.99.1
Scan saved at 10:44:53 AM, on 5/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLServiceHost.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Cookie Washer\aolwasher.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\hjt\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://store.presari...&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=1c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brazeal\Application Data\Mozilla\Profiles\default\alhwq5n1.slt\prefs.js)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107146022\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Brazeal"
O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {0F2E637F-E3AF-49BB-8BCF-2CFAEDF862EF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for ¸ĉu
: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol....oach_core_1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.t...ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EFA4DDA-C9A7-4458-9F28-DD701D193851}: NameServer = 12.127.16.77,12.127.17.77
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
#44
Posted 23 May 2006 - 08:09 PM
Can you run about:buster again and post the log.
Next
Please download Asquared from the link below.
http://www.emsisoft....tware/download/
Safe it to your desktop. Next open and check for updates.
Boot to safe mode (tap f8 while bios loads)
Then scan your system (this will take some time) after the scan is compelte allow it to fix what it has found. If there is something that it can not clean please let me know what it was.
Then reboot and post a new hijackthis log.
NEXT
Download ATF Cleaner:
http://www.atribune....tent/view/19/2/
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
When done a prompt appears informing of such.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
Then a reboot and a new hijackthis log and let me know how things are running.
#45 Guest_poporacer_*
Posted 24 May 2006 - 11:35 AM
Logfile of HijackThis v1.99.1
Scan saved at 10:17:52 AM, on 5/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Compaq\EAB\EabServr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Cookie Washer\aolwasher.exe
C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110714~1\EE\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe
C:\WINDOWS\System32\PackethSvc.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
C:\Program Files\F-Secure Internet Security\Common\FSMB32.EXE
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\Program Files\F-Secure Internet Security\Common\FCH32.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hjt\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://store.presari...&c=1c02&lc=0409
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://store.presari...&c=1c02&lc=0409
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Compaq
N2 - Netscape 6: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%206%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Brazeal\Application Data\Mozilla\Profiles\default\alhwq5n1.slt\prefs.js)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QD FastAndSafe] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107146022\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\RunServicesOnce: [washindex] C:\Program Files\Cookie Washer\washidx.exe "Brazeal"
O4 - HKCU\..\Run: [ccWasher] C:\Program Files\Cookie Washer\aolwasher.exe /0
O4 - HKCU\..\Run: [AOLCC] "C:\Program Files\AOL Computer Check-Up\ACCAgnt.exe" /startup
O4 - Global Startup: D-Link AirPlus G Configuration Utility.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Advisor - {0F2E637F-E3AF-49BB-8BCF-2CFAEDF862EF} - C:\Program Files\COMPAQ\Compaq Advisor\bin\rbaLauncher.exe (file missing) (HKCU)
O10 - Broken Internet access because of LSP provider 'connwsp.dll' missing
O12 - Plugin for .avi: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O12 - Plugin for ¸ĉu
: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin2.dll
O14 - IERESET.INF: START_PAGE_URL=http://store.presario.net/scripts/redirectors/presario/storeredir2.dll?s=consumerfav&c=1c02&lc=0409
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {37DF41B2-61DB-4CAC-A755-CFB3C7EE7F40} (AOL Content Update) - http://esupport.aol....oach_core_1.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.t...ivex/hcImpl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{0EFA4DDA-C9A7-4458-9F28-DD701D193851}: NameServer = 12.127.16.77,12.127.17.77
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure Internet Security\Common\FSMA32.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: Virtual NIC Service (PackethSvc) - America Online, Inc. - C:\WINDOWS\System32\PackethSvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Thanks again!
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users