here's the logs:
Virus Total
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name: webcheckz.dll
Submission date: 2011-03-28 00:37:54 (UTC)
Current status: queued queued analysing finished
Result: 8/ 43 (18.6%)
VT Community
not reviewed
Safety score: -
Compact Print results Antivirus Version Last Update Result
AhnLab-V3 2011.03.27.01 2011.03.27 -
AntiVir 7.11.5.87 2011.03.27 -
Antiy-AVL 2.0.3.7 2011.03.27 -
Avast 4.8.1351.0 2011.03.27 Win32:MalOb-EI
Avast5 5.0.677.0 2011.03.27 Win32:MalOb-EI
AVG 10.0.0.1190 2011.03.27 -
BitDefender 7.2 2011.03.28 Gen:Variant.Vundo.5
CAT-QuickHeal 11.00 2011.03.27 -
ClamAV 0.96.4.0 2011.03.28 -
Commtouch 5.2.11.5 2011.03.24 -
Comodo 8130 2011.03.28 -
DrWeb 5.0.2.03300 2011.03.28 -
Emsisoft 5.1.0.4 2011.03.27 Gen.Variant.Vundo!IK
eSafe 7.0.17.0 2011.03.27 -
eTrust-Vet 36.1.8236 2011.03.25 -
F-Prot 4.6.2.117 2011.03.27 -
F-Secure 9.0.16440.0 2011.03.23 Gen:Variant.Vundo.5
Fortinet 4.2.254.0 2011.03.27 -
GData 21 2011.03.28 Gen:Variant.Vundo.5
Ikarus T3.1.1.97.0 2011.03.27 Gen.Variant.Vundo
Jiangmin 13.0.900 2011.03.27 -
K7AntiVirus 9.94.4219 2011.03.26 -
Kaspersky 7.0.0.125 2011.03.28 -
McAfee 5.400.0.1158 2011.03.28 -
McAfee-GW-Edition 2010.1C 2011.03.27 -
Microsoft 1.6702 2011.03.27 -
NOD32 5990 2011.03.27 -
Norman 6.07.03 2011.03.27 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.03.27 -
PCTools 7.0.3.5 2011.03.26 -
Prevx 3.0 2011.03.28 Medium Risk Malware
Rising 23.50.05.05 2011.03.26 -
Sophos 4.64.0 2011.03.27 -
SUPERAntiSpyware 4.40.0.1006 2011.03.27 -
Symantec 20101.3.0.103 2011.03.28 -
TheHacker 6.7.0.1.159 2011.03.27 -
TrendMicro 9.200.0.1012 2011.03.27 -
TrendMicro-HouseCall 9.200.0.1012 2011.03.28 -
VBA32 3.12.14.3 2011.03.25 -
VIPRE 8841 2011.03.28 -
ViRobot 2011.3.26.4378 2011.03.27 -
VirusBuster 13.6.272.0 2011.03.27 -
Additional informationShow all
MD5 : c82bea0a0e327664f15e71ceb559dd24
SHA1 : 6bbe59384081c8abcdae7cb69681cc01ac92ea8a
SHA256: 0d08251c8c89de4abf0a1b30fd6e896c68ebdbe75571c786b2f5d8c5b298ae58
ssdeep: 3072:rZMb0TILwV2aovra7GzoVNm/0KUgwXYL:MvLPZra7GzoMUgwI
File size : 108544 bytes
First seen: 2011-03-28 00:37:54
Last seen : 2011-03-28 00:37:54
TrID:
Windows OCX File (68.1%)
Win32 Executable MS Visual C++ (generic) (20.7%)
Win32 Executable Generic (4.7%)
Win32 Dynamic Link Library (generic) (4.1%)
Generic Win/DOS Executable (1.1%)
sigcheck:
publisher….: Ijdhualae Vskxgafuqrg
copyright….: © Qhvypjqio Snbmzturhrl. All rights reserved.
product……: Caurjqrfw_ Ctxezes_ Zrhwagbqv Tavnxv
description..: Fdhygjgcm Fax Server COM Client Interface
original name: FXSCOM.DLL
internal name: FXSCOM.DLL
file version.: 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEiD: Armadillo v1.xx - v2.xx
PEInfo: PE structure information
[[ basic data ]]
entrypointaddress: 0x5A1A
timedatestamp….: 0x479FC541 (Wed Jan 30 00:30:57 2008)
machinetype……: 0x14c (I386)
[[ 5 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x7AAE, 0x7C00, 6.67, c591d351d566d566bfc106986e7fd579
.rdata, 0x9000, 0xAE2, 0xC00, 5.06, 81138579f79795a57ec0d2fa3dde6c85
.data, 0xA000, 0x13BA4, 0xB000, 4.61, 09d0190dd8a2096f06661c02d1350734
.rsrc, 0x1E000, 0x6018, 0x6200, 4.61, e83efcd5232c41677d98321e05786149
.reloc, 0x25000, 0x8E4, 0xA00, 5.50, 438cf587bdce070550ed2ca617637d84
[[ 5 import(s) ]]
KERNEL32.dll: UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentThreadId, InterlockedExchange, GetModuleHandleW, FreeLibrary, Sleep, SetUnhandledExceptionFilter, LoadLibraryW, GetProcAddress, GlobalFree, DisableThreadLibraryCalls, GetStringTypeA, LCMapStringW, LCMapStringA, GlobalAlloc, InterlockedCompareExchange, VirtualProtect, GetSystemDirectoryW, GetCommandLineA, MultiByteToWideChar, LoadLibraryA, GetOEMCP, GetACP, GetCPInfo, WriteFile, GetEnvironmentStringsW, GetStringTypeW, HeapAlloc, HeapFree, RtlUnwind, GetVersion, GetModuleHandleA, GetModuleFileNameA, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, ExitProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStrings
USER32.dll: LoadStringW, MessageBoxW
ADVAPI32.dll: RegCreateKeyExW, RegCloseKey, RegQueryValueExW, RegSetValueExW
ole32.dll: CoCreateInstance, CLSIDFromString
RPCRT4.dll: NdrDllGetClassObject, NdrCStdStubBuffer_Release, NdrDllRegisterProxy, NdrClientCall2
Prevx Info:
http://info.prevx.com/aboutprogramtext.asp…5C071003DA175A3
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 32768
CompanyName: Ijdhualae Vskxgafuqrg
EntryPoint: 0x5a1a
FileDescription: Fdhygjgcm Fax Server COM Client Interface
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 106 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 5.2.3790.1830 (srv03_sp1_rtm.050324-1447)
FileVersionNumber: 5.2.3790.1830
ImageVersion: 6.0
InitializedDataSize: 118784
InternalName: FXSCOM.DLL
LanguageCode: English (U.S.)
LegalCopyright: Qhvypjqio Snbmzturhrl. All rights reserved.
LinkerVersion: 8.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 4.0
ObjectFileType: Dynamic link library
OriginalFilename: FXSCOM.DLL
PEType: PE32
ProductName: Caurjqrfw Ctxezes Zrhwagbqv Tavnxv
ProductVersion: 5.2.3790.1830
ProductVersionNumber: 5.2.3790.1830
Subsystem: Windows GUI
SubsystemVersion: 4.0
TimeStamp: 2008:01:30 01:30:57+01:00
UninitializedDataSize: 0
Symantec reputation:Suspicious.Insight
VT Community
0
This file has never been reviewed by any VT Community member. Be the first one to comment on it!
OTL.txt Log
OTL logfile created on: 3/27/2011 5:41:07 PM - Run 4
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Mike Unser\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
766.00 Mb Total Physical Memory | 321.00 Mb Available Physical Memory | 42.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): C:\pagefile.sys 1147 1147 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.73 Gb Total Space | 65.04 Gb Free Space | 58.21% Space Free | Partition Type: NTFS
Computer Name: OFFICE | User Name: Mike Unser | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: Off | File Age = 30 Days
========== Custom Scans ==========
< C:\DOCUMENTS AND SETTINGS\MIKE UNSER\LOCAL SETTINGS\APPLICATION DATA\{AA1F7949-20DE-494A-9C69-8373D168BCBA}\*.* /s >
< MD5 for: FW20.VXD >
[2003/02/05 04:02:00 | 000,079,947 | —- | M] () MD5=FDCCFCB07A5EF1B4DA039834B07E5FE7 – C:\WINDOWS\fw20.vxd
< >
< >
< End of report >
ESET Log
ESETSmartInstaller@High as CAB hook log:
OnlineScanner.ocx - registred OK
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=8117c217123277409a330497201ad220
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-03-28 02:16:25
# local_time=2011-03-27 07:16:25 (-0700, US Mountain Standard Time)
# country="United States"
# lang=9
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 66199798 66199798 0 0
# compatibility_mode=5121 16777189 100 75 8487722 14267007 0 0
# compatibility_mode=8192 67108863 100 0 22321545 22321545 0 0
# scanned=152955
# found=4
# cleaned=0
# scan_time=4745
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0001070.dll a variant of Win32/Cimag.GK trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0003268.exe a variant of Win32/Kryptik.LWD trojan (unable to clean) 00000000000000000000000000000000 I
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP2\A0003269.exe a variant of Win32/Kryptik.LWD trojan (unable to clean) 00000000000000000000000000000000 I
C:\_OTL\MovedFiles\03272011_141251\C_Documents and Settings\Mike Unser\Application Data\defender.exe a variant of Win32/Kryptik.LZH trojan (unable to clean) 00000000000000000000000000000000 I