Logfile of HijackThis v1.99.1
Scan saved at 1:38:51 PM, on 3/11/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Documents and Settings\Jones\Desktop\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://by107fd.bay10...31ab5efb4c305c1
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O20 - Winlogon Notify: ICM - C:\WINNT\system32\f2l00c3mef.dll
O20 - Winlogon Notify: WRNotifier - C:\WINNT\SYSTEM32\WRLogonNTF.dll
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Remote Procedure Call (RPC) Service (RpcSssvc) - Unknown owner - C:\WINNT\system32\RpcSs.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access
*Not everything listed here means you are infected!
________________________________________________
C:\WINNT\SYSTEM32\f2l00c~1.dll Sat Mar 11 2006 11:35:42a ..S.R 233,875 228.39 K
C:\WINNT\SYSTEM32\jut.dll Sat Mar 11 2006 1:36:34p ..S.R 233,875 228.39 K
C:\WINNT\SYSTEM32\r46ule~1.dll Sat Mar 11 2006 1:36:34p ..S.R 235,839 230.31 K
________________________________________________
1,043 items found: 1,043 files (3 H/S), 0 directories.
Total of file sizes: 189,989,112 bytes 181.19 M
Administrator Account = True
--------------------End log---------------------
********
12:45 PM: | Start of Session, Saturday, March 11, 2006 |
12:45 PM: Spy Sweeper started
12:45 PM: Sweep initiated using definitions version 630
12:46 PM: Starting Memory Sweep
12:50 PM: Memory Sweep Complete, Elapsed Time: 00:04:37
12:50 PM: Starting Registry Sweep
12:51 PM: Found System Monitor: sc-keylog
12:51 PM: HKLM\software\microsoft\windows nt\currentversion\winlogon\notify\explorer\ (6 subtraces) (ID = 140468)
12:51 PM: Registry Sweep Complete, Elapsed Time:00:00:49
12:51 PM: Starting Cookie Sweep
12:51 PM: Found Spy Cookie: addynamix cookie
12:51 PM: jones@ads.addynamix[1].txt (ID = 2062)
12:51 PM: Found Spy Cookie: bluestreak cookie
12:51 PM: jones@bluestreak[1].txt (ID = 2314)
12:51 PM: Found Spy Cookie: burstnet cookie
12:51 PM: jones@burstnet[2].txt (ID = 2336)
12:51 PM: Found Spy Cookie: casalemedia cookie
12:51 PM: jones@casalemedia[1].txt (ID = 2354)
12:51 PM: Found Spy Cookie: burstbeacon cookie
12:51 PM: jones@www.burstbeacon[1].txt (ID = 2335)
12:51 PM: Found Spy Cookie: adserver cookie
12:51 PM: jones@z1.adserver[1].txt (ID = 2142)
12:51 PM: Found Spy Cookie: zedo cookie
12:51 PM: jones@zedo[2].txt (ID = 3762)
12:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
12:51 PM: Starting File Sweep
12:58 PM: Found Adware: look2me
12:58 PM: wzpcd.dll (ID = 159)
1:11 PM: wzpcd.dll (ID = 159)
1:18 PM: pkdgen.dll (ID = 159)
1:22 PM: jmbexec.dll (ID = 159)
1:27 PM: File Sweep Complete, Elapsed Time: 00:35:50
1:27 PM: Full Sweep has completed. Elapsed time 00:41:30
1:27 PM: Traces Found: 18
1:29 PM: Removal process initiated
1:29 PM: Quarantining All Traces: look2me
1:29 PM: Quarantining All Traces: sc-keylog
1:29 PM: Quarantining All Traces: addynamix cookie
1:29 PM: Quarantining All Traces: adserver cookie
1:29 PM: Quarantining All Traces: bluestreak cookie
1:29 PM: Quarantining All Traces: burstbeacon cookie
1:29 PM: Quarantining All Traces: burstnet cookie
1:29 PM: Quarantining All Traces: casalemedia cookie
1:29 PM: Quarantining All Traces: zedo cookie
1:30 PM: Removal process completed. Elapsed time 00:01:07
********
2:04 PM: | Start of Session, Friday, March 10, 2006 |
2:04 PM: Spy Sweeper started
2:04 PM: Sweep initiated using definitions version 630
2:04 PM: Found Adware: quicklink search toolbar
2:04 PM: HKCR\clsid\{f4c522e0-5bd5-407b-99a3-5a435db6694a}\inprocserver32\ (2 subtraces) (ID = 1190418)
2:04 PM: v9gcyb8xi.dll (ID = 1190418)
2:04 PM: HKCR\clsid\{156afb23-6a31-443c-a1d0-fd418898c11b}\inprocserver32\ (2 subtraces) (ID = 1190420)
2:04 PM: v9gcyb8xi.dll (ID = 1190420)
2:04 PM: Starting Memory Sweep
2:06 PM: Warning: Failed to check file "C:\WINNT\system32\e6200gfme62a0.dll". Stream read error
2:07 PM: Found Adware: command
2:07 PM: Detected running threat: C:\WINNT\Sm9uZXM\command.exe (ID = 144946)
2:09 PM: Detected running threat: C:\WINNT\Sm9uZXM\asappsrv.dll (ID = 144945)
2:09 PM: Warning: Failed to check file "C:\WINNT\system32\pkdgen.dll". Stream read error
2:10 PM: Memory Sweep Complete, Elapsed Time: 00:05:22
2:10 PM: Starting Registry Sweep
2:11 PM: Found Adware: enbrowser
2:11 PM: HKLM\software\system\sysold\ (2 subtraces) (ID = 926808)
2:11 PM: HKLM\system\currentcontrolset\services\cmdservice\ (12 subtraces) (ID = 958670)
2:11 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\0000\ (8 subtraces) (ID = 1016064)
2:11 PM: HKLM\system\currentcontrolset\enum\root\legacy_cmdservice\ (10 subtraces) (ID = 1016072)
2:11 PM: HKCR\fseytdc.ariaqudok\ (3 subtraces) (ID = 1180460)
2:11 PM: HKCR\fseytdc.ariaqudok.1\ (3 subtraces) (ID = 1180464)
2:11 PM: HKCR\fseytdc.yvakt\ (3 subtraces) (ID = 1180468)
2:11 PM: HKCR\fseytdc.yvakt.1\ (3 subtraces) (ID = 1180472)
2:11 PM: HKCR\clsid\{156afb23-6a31-443c-a1d0-fd418898c11b}\ (8 subtraces) (ID = 1180476)
2:11 PM: HKCR\clsid\{f4c522e0-5bd5-407b-99a3-5a435db6694a}\ (8 subtraces) (ID = 1180485)
2:11 PM: HKCR\typelib\{e3b39f3e-a325-48b2-a4b0-c27d8becf90d}\ (9 subtraces) (ID = 1180496)
2:11 PM: HKLM\software\classes\fseytdc.ariaqudok\ (3 subtraces) (ID = 1180510)
2:11 PM: HKLM\software\classes\fseytdc.ariaqudok.1\ (3 subtraces) (ID = 1180514)
2:11 PM: HKLM\software\classes\fseytdc.yvakt\ (3 subtraces) (ID = 1180518)
2:11 PM: HKLM\software\classes\fseytdc.yvakt.1\ (3 subtraces) (ID = 1180522)
2:11 PM: HKLM\software\classes\clsid\{156afb23-6a31-443c-a1d0-fd418898c11b}\ (8 subtraces) (ID = 1180539)
2:11 PM: HKLM\software\classes\clsid\{f4c522e0-5bd5-407b-99a3-5a435db6694a}\ (8 subtraces) (ID = 1180548)
2:11 PM: HKLM\software\classes\typelib\{e3b39f3e-a325-48b2-a4b0-c27d8becf90d}\ (9 subtraces) (ID = 1180559)
2:11 PM: HKU\S-1-5-21-1935655697-1677128483-1060284298-1000\software\system\sysuid\ (1 subtraces) (ID = 731748)
2:11 PM: Registry Sweep Complete, Elapsed Time:00:01:16