raf
Topic Starter
Hello everyone. I'm a new member but I have read with great interest many of the great posts in here as a lurker. I now know I need your professional assistance as the adware I keep finding on my system redirects me to new web pages every time I open my browser. Below are my HJThis log, SpyBot log and Ad-Aware SE log. I downloaded the FxAgentB program and it found nothing and CWShredder found cws.BootConf and cws.Svchost32.
Logfile of HijackThis v1.99.0
Scan saved at 9:00:11 AM, on 1/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\owurkq.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT 1.99\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinMem] C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Registry Management Service - Unknown - C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SpyBot log:
— Search result list —
Cache: Cache (353) (Cache, nothing done)
Common Dialogs: History (6 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Common hijacker: Redirected host (Redirected host, nothing done)
Common hijacker: Redirected host (Redirected host, nothing done)
Cookie: Cookie (7) (Cookie, nothing done)
CoolWWWSearch.Bootconf: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Loadbat: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Msconfd: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Oslogo: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Tapicfg: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Xmlmimefilter: Redirected host (Redirected host, nothing done)
IGetNet: Redirected host (Redirected host, nothing done)
Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiprov.log
Log: Activity: ntbtlog.txt (Backup file, nothing done)
C:\WINDOWS\ntbtlog.txt
Log: Activity: SchedLgU.Txt (Backup file, nothing done)
C:\WINDOWS\SchedLgU.Txt
Log: Install: setupapi.log (Backup file, nothing done)
C:\WINDOWS\setupapi.log
Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.log
VBouncer: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3995174488-2579519877-2797410178-1005\Software\VB and VBA Program Settings\VBouncer
Virtual Bouncer: Program directory (Directory, nothing done)
C:\Program Files\VBOUNCER\
Virtual Bouncer: Cryptography services (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Services\DistID
— Spybot - Search && Destroy version: 1.3 —
2004-11-29 Includes\Cookies.sbi
2004-12-15 Includes\Dialer.sbi
2004-12-16 Includes\Hijackers.sbi
2004-12-15 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2004-12-15 Includes\Malware.sbi
2004-11-29 Includes\Revision.sbi
2004-11-29 Includes\Security.sbi
2004-12-16 Includes\Spybots.sbi
2004-11-29 Includes\Tracks.uti
2004-12-15 Includes\Trojans.sbi
— System information —
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX / DX9 / SP1: DirectX 9 Hotfix - KB839643
/ Windows Media Player: Windows Media Player Hotfix [See KB837272 for more information]
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 819639
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
— Startup entries list —
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 71280
MD5: 22755776eccc7165ac109c381782a957
Located: HK_LM:Run, ezShieldProtector for Px
command: C:\WINDOWS\System32\ezSP_Px.exe
file: C:\WINDOWS\System32\ezSP_Px.exe
size: 40960
MD5: 2849ed071a0d83406bda342aa767f24e
Located: HK_LM:Run, HKSERV.EXE
command: C:\Program Files\Sony\HotKey Utility\HKserv.exe
file: C:\Program Files\Sony\HotKey Utility\HKserv.exe
size: 94208
MD5: e732011652d184e68628f3ac7dc46438
Located: HK_LM:Run, Logitech Utility
command: Logi_MwX.Exe
file: C:\WINDOWS\Logi_MwX.Exe
size: 19968
MD5: 290bbfaaa1ee80a4a971b86f1c5de1dd
Located: HK_LM:Run, Narrator
command: C:\WINDOWS\system32\owurkq.exe
file: C:\WINDOWS\system32\owurkq.exe
size: 33280
MD5: 61cfa0ded5666d451158c6f9a9a75854
Located: HK_LM:Run, SonyPowerCfg
command: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
file: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
size: 167936
MD5: d9c35ec1eae11352fe86ba72717fd991
Located: HK_LM:Run, Symantec NetDriver Monitor
command: C:\PROGRA~1\SYMNET~1\SNDMon.exe
file: C:\PROGRA~1\SYMNET~1\SNDMon.exe
size: 95456
MD5: 46462b246bcb76450178a7260617cebd
Located: HK_LM:Run, SynTPEnh
command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 499712
MD5: 79400ac73fa493b18507147e49fc4264
Located: HK_LM:Run, SynTPLpr
command: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
file: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
size: 98304
MD5: a20fca725e42b48d559b1247546d2399
Located: HK_LM:Run, URLLSTCK.exe
command: C:\Program Files\Norton Internet Security\UrlLstCk.exe
file: C:\Program Files\Norton Internet Security\UrlLstCk.exe
size: 70800
MD5: 82ad82d69906784633f51dd7ca2248d8
Located: HK_LM:Run, VAIO Update 2
command: "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
file: C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
size: 135168
MD5: c3db0253c1ad4a7eaaadef5b5fc6681e
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, LDM
command: \Program\BackWeb-8876480.exe
Located: HK_CU:Run, WinMem
command: C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
file: C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
size: 493056
MD5: 692ab03642e27ad315bf8eb0756a7f9d
Located: Startup (common), Acrobat Assistant.lnk
command: C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
file: C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
size: 217193
MD5: 78bfe3201ada2fe02d1e35d2488e5f55
Located: Startup (common), DataViz Inc Messenger.lnk
command: C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
file: C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
size: 24576
MD5: 4a830bbb3217ea53d731502c07abcac6
Located: Startup (common), HotSync Manager.lnk
command: C:\Program Files\Sony Handheld\HOTSYNC.EXE
file: C:\Program Files\Sony Handheld\HOTSYNC.EXE
size: 299008
MD5: 7fb566c5816d8959c9f3ab918c00cd1f
Located: Startup (common), Logitech Desktop Messenger.lnk
command: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
file: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
size: 450560
MD5: 475091aecf6a4dd6b3e641020a17bac8
Located: Startup (common), QuickBooks Update Agent.lnk
command: C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
file: C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
size: 724992
MD5: 6a7760249238783f8ad92f79d9c9faf9
— Browser helper object list —
— ActiveX list —
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 8/27/2003 3:10:30 AM
Date (last access): 1/4/2005 9:13:42 AM
Date (last write): 8/27/2003 3:10:30 AM
Filesize: 314368
Attributes: archive
MD5: 1E32EC4A8A17B19926B49EA5F6B79A76
CRC32: E98FC293
Version: 0.11.0.0
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_01
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\j2re1.4.2_01\bin\
Long name: NPJPI142_01.dll
Short name: NPJPI1~1.DLL
Date (created): 8/19/2067 8:23:36 PM
Date (last access): 1/3/2005 1:11:56 PM
Date (last write): 8/19/2003 8:23:34 PM
Filesize: 65642
Attributes: archive
MD5: 0B668A48CB4845F9D9D335D99C82504C
CRC32: B9AD4E66
Version: 0.1.0.4
{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla
{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_01
Path: C:\Program Files\Java\j2re1.4.2_01\bin\
Long name: NPJPI142_01.dll
Short name: NPJPI1~1.DLL
Date (created): 8/19/2067 8:23:36 PM
Date (last access): 1/4/2005 9:24:34 AM
Date (last write): 8/19/2003 8:23:34 PM
Filesize: 65642
Attributes: archive
MD5: 0B668A48CB4845F9D9D335D99C82504C
CRC32: B9AD4E66
Version: 0.1.0.4
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\macromed\flash\
Long name: Flash.ocx
Short name:
Date (created): 4/8/2004 4:51:02 PM
Date (last access): 1/4/2005 9:12:16 AM
Date (last write): 6/9/2004 3:59:26 PM
Filesize: 939224
Attributes: archive
MD5: FC3E17E12C2E31FAC34B416B3DAB829F
CRC32: D1CF3A57
Version: 0.7.0.0
— Process list —
Spybot - Search && Destroy process list report, 1/4/2005 9:24:36 AM
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 364 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
PID: 480 (2360) C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
PID: 488 ( 4) \SystemRoot\System32\smss.exe
PID: 544 ( 488) csrss.exe
PID: 568 ( 488) \??\C:\WINDOWS\system32\winlogon.exe
PID: 616 ( 568) C:\WINDOWS\system32\services.exe
PID: 628 ( 568) C:\WINDOWS\system32\lsass.exe
PID: 740 ( 800) C:\Program Files\Messenger\msmsgs.exe
PID: 780 ( 616) C:\WINDOWS\System32\Ati2evxx.exe
PID: 800 ( 616) C:\WINDOWS\system32\svchost.exe
PID: 856 ( 616) svchost.exe
PID: 908 ( 616) C:\WINDOWS\System32\svchost.exe
PID: 936 ( 800) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
PID: 992 ( 616) svchost.exe
PID: 1048 ( 616) svchost.exe
PID: 1192 ( 568) C:\WINDOWS\system32\rundll32.exe
PID: 1232 ( 616) C:\WINDOWS\system32\spoolsv.exe
PID: 1332 ( 616) C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
PID: 1352 ( 616) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1388 ( 616) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 1420 ( 616) C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
PID: 1528 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
PID: 1548 ( 616) C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
PID: 1576 ( 616) C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
PID: 1592 (2360) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PID: 1620 ( 616) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1656 ( 616) C:\WINDOWS\System32\svchost.exe
PID: 1688 ( 616) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 1780 ( 616) wdfmgr.exe
PID: 1864 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
PID: 1920 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
PID: 1968 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
PID: 1980 ( 616) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 2004 ( 616) C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PID: 2116 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
PID: 2612 ( 616) alg.exe
PID: 2740 (2360) C:\Program Files\Internet Explorer\iexplore.exe
PID: 2780 (2360) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 2788 (2360) C:\Program Files\Sony\HotKey Utility\HKserv.exe
PID: 2796 (2360) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PID: 2804 (2360) C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
PID: 2812 (2360) C:\WINDOWS\System32\ezSP_Px.exe
PID: 2852 (2360) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2948 (2360) C:\WINDOWS\system32\ctfmon.exe
PID: 2980 (2360) C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
PID: 2984 (2360) C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
PID: 3056 (2820) C:\Program Files\Logitech\MouseWare\system\em_exec.exe
PID: 3108 (2360) C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PID: 3120 (2360) C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
PID: 3136 (2360) C:\Program Files\Sony Handheld\HOTSYNC.EXE
PID: 3184 (2360) C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
PID: 3336 (2788) C:\Program Files\Sony\HotKey Utility\HKWnd.exe
PID: 3508 ( 568) C:\WINDOWS\explorer.exe
PID: 3640 ( 616) C:\WINDOWS\System32\svchost.exe
— Browser start & search pages list —
Spybot - Search && Destroy browser pages report, 1/4/2005 9:24:36 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
c:\windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.yahoo.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
c:\windows\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm
— Winsock Layered Service Provider list —
Protocol 0: calsp over [aklsp.dll over [MSAFD Tcpip [TCP/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 1: calsp over [aklsp.dll over [MSAFD Tcpip [UDP/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 2: calsp over [aklsp.dll over [MSAFD Tcpip [RAW/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 3: aklsp.dll over [MSAFD Tcpip [TCP/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 4: aklsp.dll over [MSAFD Tcpip [UDP/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 5: aklsp.dll over [MSAFD Tcpip [RAW/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 6: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 7: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 8: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 9: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 10: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46554835-5934-4563-8B75-8864C461FA80}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46554835-5934-4563-8B75-8864C461FA80}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{135FBE41-9E13-47C0-BE21-63A56F71D948}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{135FBE41-9E13-47C0-BE21-63A56F71D948}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5262143-165E-4678-BA24-C9E33E0BEE72}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5262143-165E-4678-BA24-C9E33E0BEE72}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71C9A585-C163-4881-88AD-BE238181AB59}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71C9A585-C163-4881-88AD-BE238181AB59}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE3B13CD-8834-47AF-B0EC-EAEA12D19258}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE3B13CD-8834-47AF-B0EC-EAEA12D19258}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{25EB441F-11B0-4EAE-9F81-0EE003A82358}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{25EB441F-11B0-4EAE-9F81-0EE003A82358}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 23: aklsp.dll
GUID: {9FFE79E9-BFAB-49D5-B461-7A38B71A8EE8}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 24: calsp
GUID: {CD395805-A77B-401F-B1AC-A3A409EF16BB}
Filename: C:\WINDOWS\system32\calsp.dll
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Ad-Aware SE log:
ArchiveData(auto-quarantine- 2005-01-04 09-29-02.bckp)
Referencefile : SE1R24 29.12.2004
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[1]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\exe
obj[2]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.doc
obj[3]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj[5]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[4]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.TXT
obj[7]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\Application Data\microsoft\office\recent\index.dat
obj[8]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ad-Aware Quarantine List 2 (1-3-05).TXT.lnk
obj[9]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\FxAgentB.log.lnk
obj[10]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\hijackthis.log.lnk
obj[11]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Letter to Jeremy Mason of January 3, 2005.doc.lnk
obj[12]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Letter to Jeremy Mason of November 19, 2004.doc.lnk
obj[13]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ltr to clnt of January 3, 2005 re December invoices.doc.lnk
obj[14]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ltr to clnt of October 20, 2004 re status of case.doc.lnk
obj[15]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Mason, Slovin & Schilling.lnk
obj[16]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Recovery Zone-Fleece.lnk
obj[17]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\SpybotSD.Report.txt.lnk
VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[9]=Process : C:\WINDOWS\system32\o0lu0a39ed.dll
obj[10]=Process : C:\WINDOWS\system32\nnxpnt.dll
obj[12]=Process : C:\WINDOWS\system32\nnxpnt.dll
obj[14]=Process : C:\WINDOWS\system32\owurkq.exe
obj[23]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[24]=RegValue : software\microsoft\windows\currentversion\run "Narrator"
COOLWEBSEARCH
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[11]=Process : C:\WINDOWS\system32\uepbas.dll
obj[13]=Process : C:\WINDOWS\system32\uepbas.dll
obj[15]=Process : C:\WINDOWS\system32\uepbas.dll
obj[16]=Process : C:\WINDOWS\system32\uepbas.dll
obj[25]=RegValue : software\microsoft\internet explorer\main "Enable Browser Extensions"
obj[26]=RegValue : software\microsoft\internet explorer\main "Use Custom Search URL"
obj[27]=RegValue : software\microsoft\internet explorer\main "Search Bar"
ADDESTROYER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[17]=Regkey : S-1-5-21-3995174488-2579519877-2797410178-1005\software\vb and vba program settings\addestroyer
obj[28]=Folder : C:\Program Files\AdDestroyer
obj[30]=File : C:\WINDOWS\system32\PopOops.dll
obj[31]=File : C:\WINDOWS\system32\PopOops2.dll
obj[32]=File : C:\WINDOWS\system32\SWLAD1.dll
obj[33]=File : C:\WINDOWS\system32\SWLAD2.dll
VIRTUALBOUNCER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[18]=Regkey : S-1-5-21-3995174488-2579519877-2797410178-1005\software\vb and vba program settings\vbouncer
obj[19]=RegValue : software\microsoft\cryptography\services "DistID"
obj[29]=Folder : C:\Program Files\VBouncer
REDIRECTED HOSTFILE ENTRY
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[20]=Hosts file : 69.20.16.183 auto.search.msn.com
obj[21]=Hosts file : 69.20.16.183 search.netscape.com
obj[22]=Hosts file : 69.20.16.183 ieautosearch
Any help would be greatly appreciated. Thanks.
Logfile of HijackThis v1.99.0
Scan saved at 9:00:11 AM, on 1/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\owurkq.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Sony\HotKey Utility\HKserv.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
C:\Program Files\Sony Handheld\HOTSYNC.EXE
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Sony\HotKey Utility\HKWnd.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT 1.99\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HKSERV.EXE] C:\Program Files\Sony\HotKey Utility\HKserv.exe
O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinMem] C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\Sony Handheld\HOTSYNC.EXE
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\aklsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Registry Management Service - Unknown - C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
O23 - Service: VAIO Media Music Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Music Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Photo Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
O23 - Service: VAIO Media Video Server (HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Video Server (UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
SpyBot log:
— Search result list —
Cache: Cache (353) (Cache, nothing done)
Common Dialogs: History (6 files) (Registry key, nothing done)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU
Common hijacker: Redirected host (Redirected host, nothing done)
Common hijacker: Redirected host (Redirected host, nothing done)
Cookie: Cookie (7) (Cookie, nothing done)
CoolWWWSearch.Bootconf: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Loadbat: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Msconfd: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Oslogo: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Tapicfg: Redirected host (Redirected host, nothing done)
CoolWWWSearch.Xmlmimefilter: Redirected host (Redirected host, nothing done)
IGetNet: Redirected host (Redirected host, nothing done)
Log: Shutdown: System32\wbem\logs\wmiprov.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiprov.log
Log: Activity: ntbtlog.txt (Backup file, nothing done)
C:\WINDOWS\ntbtlog.txt
Log: Activity: SchedLgU.Txt (Backup file, nothing done)
C:\WINDOWS\SchedLgU.Txt
Log: Install: setupapi.log (Backup file, nothing done)
C:\WINDOWS\setupapi.log
Log: Shutdown: System32\wbem\logs\wbemess.log (Backup file, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.log
VBouncer: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-3995174488-2579519877-2797410178-1005\Software\VB and VBA Program Settings\VBouncer
Virtual Bouncer: Program directory (Directory, nothing done)
C:\Program Files\VBOUNCER\
Virtual Bouncer: Cryptography services (Registry value, nothing done)
HKEY_LOCAL_MACHINE\Software\Microsoft\Cryptography\Services\DistID
— Spybot - Search && Destroy version: 1.3 —
2004-11-29 Includes\Cookies.sbi
2004-12-15 Includes\Dialer.sbi
2004-12-16 Includes\Hijackers.sbi
2004-12-15 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2004-12-15 Includes\Malware.sbi
2004-11-29 Includes\Revision.sbi
2004-11-29 Includes\Security.sbi
2004-12-16 Includes\Spybots.sbi
2004-11-29 Includes\Tracks.uti
2004-12-15 Includes\Trojans.sbi
— System information —
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Security update for Microsoft Data Access Components
/ DataAccess: Security Update for Microsoft Data Access Components
/ DirectX / DX9 / SP1: DirectX 9 Hotfix - KB839643
/ Windows Media Player: Windows Media Player Hotfix [See KB837272 for more information]
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 819639
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Windows XP Hotfix - KB834707
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
— Startup entries list —
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 71280
MD5: 22755776eccc7165ac109c381782a957
Located: HK_LM:Run, ezShieldProtector for Px
command: C:\WINDOWS\System32\ezSP_Px.exe
file: C:\WINDOWS\System32\ezSP_Px.exe
size: 40960
MD5: 2849ed071a0d83406bda342aa767f24e
Located: HK_LM:Run, HKSERV.EXE
command: C:\Program Files\Sony\HotKey Utility\HKserv.exe
file: C:\Program Files\Sony\HotKey Utility\HKserv.exe
size: 94208
MD5: e732011652d184e68628f3ac7dc46438
Located: HK_LM:Run, Logitech Utility
command: Logi_MwX.Exe
file: C:\WINDOWS\Logi_MwX.Exe
size: 19968
MD5: 290bbfaaa1ee80a4a971b86f1c5de1dd
Located: HK_LM:Run, Narrator
command: C:\WINDOWS\system32\owurkq.exe
file: C:\WINDOWS\system32\owurkq.exe
size: 33280
MD5: 61cfa0ded5666d451158c6f9a9a75854
Located: HK_LM:Run, SonyPowerCfg
command: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
file: C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
size: 167936
MD5: d9c35ec1eae11352fe86ba72717fd991
Located: HK_LM:Run, Symantec NetDriver Monitor
command: C:\PROGRA~1\SYMNET~1\SNDMon.exe
file: C:\PROGRA~1\SYMNET~1\SNDMon.exe
size: 95456
MD5: 46462b246bcb76450178a7260617cebd
Located: HK_LM:Run, SynTPEnh
command: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
file: C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
size: 499712
MD5: 79400ac73fa493b18507147e49fc4264
Located: HK_LM:Run, SynTPLpr
command: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
file: C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
size: 98304
MD5: a20fca725e42b48d559b1247546d2399
Located: HK_LM:Run, URLLSTCK.exe
command: C:\Program Files\Norton Internet Security\UrlLstCk.exe
file: C:\Program Files\Norton Internet Security\UrlLstCk.exe
size: 70800
MD5: 82ad82d69906784633f51dd7ca2248d8
Located: HK_LM:Run, VAIO Update 2
command: "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
file: C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
size: 135168
MD5: c3db0253c1ad4a7eaaadef5b5fc6681e
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, LDM
command: \Program\BackWeb-8876480.exe
Located: HK_CU:Run, WinMem
command: C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
file: C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
size: 493056
MD5: 692ab03642e27ad315bf8eb0756a7f9d
Located: Startup (common), Acrobat Assistant.lnk
command: C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
file: C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
size: 217193
MD5: 78bfe3201ada2fe02d1e35d2488e5f55
Located: Startup (common), DataViz Inc Messenger.lnk
command: C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
file: C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
size: 24576
MD5: 4a830bbb3217ea53d731502c07abcac6
Located: Startup (common), HotSync Manager.lnk
command: C:\Program Files\Sony Handheld\HOTSYNC.EXE
file: C:\Program Files\Sony Handheld\HOTSYNC.EXE
size: 299008
MD5: 7fb566c5816d8959c9f3ab918c00cd1f
Located: Startup (common), Logitech Desktop Messenger.lnk
command: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
file: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
size: 450560
MD5: 475091aecf6a4dd6b3e641020a17bac8
Located: Startup (common), QuickBooks Update Agent.lnk
command: C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
file: C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
size: 724992
MD5: 6a7760249238783f8ad92f79d9c9faf9
— Browser helper object list —
— ActiveX list —
{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 8/27/2003 3:10:30 AM
Date (last access): 1/4/2005 9:13:42 AM
Date (last write): 8/27/2003 3:10:30 AM
Filesize: 314368
Attributes: archive
MD5: 1E32EC4A8A17B19926B49EA5F6B79A76
CRC32: E98FC293
Version: 0.11.0.0
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_01
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\j2re1.4.2_01\bin\
Long name: NPJPI142_01.dll
Short name: NPJPI1~1.DLL
Date (created): 8/19/2067 8:23:36 PM
Date (last access): 1/3/2005 1:11:56 PM
Date (last write): 8/19/2003 8:23:34 PM
Filesize: 65642
Attributes: archive
MD5: 0B668A48CB4845F9D9D335D99C82504C
CRC32: B9AD4E66
Version: 0.1.0.4
{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla
{CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2_01
Path: C:\Program Files\Java\j2re1.4.2_01\bin\
Long name: NPJPI142_01.dll
Short name: NPJPI1~1.DLL
Date (created): 8/19/2067 8:23:36 PM
Date (last access): 1/4/2005 9:24:34 AM
Date (last write): 8/19/2003 8:23:34 PM
Filesize: 65642
Attributes: archive
MD5: 0B668A48CB4845F9D9D335D99C82504C
CRC32: B9AD4E66
Version: 0.1.0.4
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\macromed\flash\
Long name: Flash.ocx
Short name:
Date (created): 4/8/2004 4:51:02 PM
Date (last access): 1/4/2005 9:12:16 AM
Date (last write): 6/9/2004 3:59:26 PM
Filesize: 939224
Attributes: archive
MD5: FC3E17E12C2E31FAC34B416B3DAB829F
CRC32: D1CF3A57
Version: 0.7.0.0
— Process list —
Spybot - Search && Destroy process list report, 1/4/2005 9:24:36 AM
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 364 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
PID: 480 (2360) C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
PID: 488 ( 4) \SystemRoot\System32\smss.exe
PID: 544 ( 488) csrss.exe
PID: 568 ( 488) \??\C:\WINDOWS\system32\winlogon.exe
PID: 616 ( 568) C:\WINDOWS\system32\services.exe
PID: 628 ( 568) C:\WINDOWS\system32\lsass.exe
PID: 740 ( 800) C:\Program Files\Messenger\msmsgs.exe
PID: 780 ( 616) C:\WINDOWS\System32\Ati2evxx.exe
PID: 800 ( 616) C:\WINDOWS\system32\svchost.exe
PID: 856 ( 616) svchost.exe
PID: 908 ( 616) C:\WINDOWS\System32\svchost.exe
PID: 936 ( 800) C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
PID: 992 ( 616) svchost.exe
PID: 1048 ( 616) svchost.exe
PID: 1192 ( 568) C:\WINDOWS\system32\rundll32.exe
PID: 1232 ( 616) C:\WINDOWS\system32\spoolsv.exe
PID: 1332 ( 616) C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
PID: 1352 ( 616) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 1388 ( 616) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 1420 ( 616) C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
PID: 1528 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
PID: 1548 ( 616) C:\Program Files\blcorp\WCCSC\RegOpt\RegManServ.exe
PID: 1576 ( 616) C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
PID: 1592 (2360) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PID: 1620 ( 616) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1656 ( 616) C:\WINDOWS\System32\svchost.exe
PID: 1688 ( 616) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 1780 ( 616) wdfmgr.exe
PID: 1864 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
PID: 1920 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
PID: 1968 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
PID: 1980 ( 616) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 2004 ( 616) C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
PID: 2116 ( 616) C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
PID: 2612 ( 616) alg.exe
PID: 2740 (2360) C:\Program Files\Internet Explorer\iexplore.exe
PID: 2780 (2360) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PID: 2788 (2360) C:\Program Files\Sony\HotKey Utility\HKserv.exe
PID: 2796 (2360) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
PID: 2804 (2360) C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
PID: 2812 (2360) C:\WINDOWS\System32\ezSP_Px.exe
PID: 2852 (2360) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2948 (2360) C:\WINDOWS\system32\ctfmon.exe
PID: 2980 (2360) C:\Program Files\blcorp\WCCSC\WinMem\WinMem.exe
PID: 2984 (2360) C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
PID: 3056 (2820) C:\Program Files\Logitech\MouseWare\system\em_exec.exe
PID: 3108 (2360) C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
PID: 3120 (2360) C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe
PID: 3136 (2360) C:\Program Files\Sony Handheld\HOTSYNC.EXE
PID: 3184 (2360) C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
PID: 3336 (2788) C:\Program Files\Sony\HotKey Utility\HKWnd.exe
PID: 3508 ( 568) C:\WINDOWS\explorer.exe
PID: 3640 ( 616) C:\WINDOWS\System32\svchost.exe
— Browser start & search pages list —
Spybot - Search && Destroy browser pages report, 1/4/2005 9:24:36 AM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
c:\windows\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.yahoo.com/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
c:\windows\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dll?p…er=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchcust.htm
— Winsock Layered Service Provider list —
Protocol 0: calsp over [aklsp.dll over [MSAFD Tcpip [TCP/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 1: calsp over [aklsp.dll over [MSAFD Tcpip [UDP/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 2: calsp over [aklsp.dll over [MSAFD Tcpip [RAW/IP]]]
GUID: {2A0B5C9C-F356-4B0B-8DB1-EB3E4F7A016F}
Filename: C:\WINDOWS\system32\calsp.dll
Protocol 3: aklsp.dll over [MSAFD Tcpip [TCP/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 4: aklsp.dll over [MSAFD Tcpip [UDP/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 5: aklsp.dll over [MSAFD Tcpip [RAW/IP]]
GUID: {1201514D-C4D2-49D2-BAAD-F2F87B65D809}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 6: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 7: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 8: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 9: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 10: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46554835-5934-4563-8B75-8864C461FA80}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{46554835-5934-4563-8B75-8864C461FA80}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{135FBE41-9E13-47C0-BE21-63A56F71D948}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{135FBE41-9E13-47C0-BE21-63A56F71D948}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5262143-165E-4678-BA24-C9E33E0BEE72}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{D5262143-165E-4678-BA24-C9E33E0BEE72}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71C9A585-C163-4881-88AD-BE238181AB59}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71C9A585-C163-4881-88AD-BE238181AB59}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 19: MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE3B13CD-8834-47AF-B0EC-EAEA12D19258}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 20: MSAFD NetBIOS [\Device\NetBT_Tcpip_{AE3B13CD-8834-47AF-B0EC-EAEA12D19258}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 21: MSAFD NetBIOS [\Device\NetBT_Tcpip_{25EB441F-11B0-4EAE-9F81-0EE003A82358}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 22: MSAFD NetBIOS [\Device\NetBT_Tcpip_{25EB441F-11B0-4EAE-9F81-0EE003A82358}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 23: aklsp.dll
GUID: {9FFE79E9-BFAB-49D5-B461-7A38B71A8EE8}
Filename: C:\WINDOWS\system32\aklsp.dll
Protocol 24: calsp
GUID: {CD395805-A77B-401F-B1AC-A3A409EF16BB}
Filename: C:\WINDOWS\system32\calsp.dll
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
Ad-Aware SE log:
ArchiveData(auto-quarantine- 2005-01-04 09-29-02.bckp)
Referencefile : SE1R24 29.12.2004
======================================================
MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[1]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\exe
obj[2]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.doc
obj[3]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj[5]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[4]=MRU RegReference : S-1-5-21-3995174488-2579519877-2797410178-1005\software\microsoft\windows\currentversion\explorer\recentdocs\.TXT
obj[7]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\Application Data\microsoft\office\recent\index.dat
obj[8]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ad-Aware Quarantine List 2 (1-3-05).TXT.lnk
obj[9]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\FxAgentB.log.lnk
obj[10]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\hijackthis.log.lnk
obj[11]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Letter to Jeremy Mason of January 3, 2005.doc.lnk
obj[12]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Letter to Jeremy Mason of November 19, 2004.doc.lnk
obj[13]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ltr to clnt of January 3, 2005 re December invoices.doc.lnk
obj[14]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Ltr to clnt of October 20, 2004 re status of case.doc.lnk
obj[15]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Mason, Slovin & Schilling.lnk
obj[16]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\Recovery Zone-Fleece.lnk
obj[17]=MRU FileReference : C:\Documents and Settings\Rob Flaugher\recent\SpybotSD.Report.txt.lnk
VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[9]=Process : C:\WINDOWS\system32\o0lu0a39ed.dll
obj[10]=Process : C:\WINDOWS\system32\nnxpnt.dll
obj[12]=Process : C:\WINDOWS\system32\nnxpnt.dll
obj[14]=Process : C:\WINDOWS\system32\owurkq.exe
obj[23]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[24]=RegValue : software\microsoft\windows\currentversion\run "Narrator"
COOLWEBSEARCH
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[11]=Process : C:\WINDOWS\system32\uepbas.dll
obj[13]=Process : C:\WINDOWS\system32\uepbas.dll
obj[15]=Process : C:\WINDOWS\system32\uepbas.dll
obj[16]=Process : C:\WINDOWS\system32\uepbas.dll
obj[25]=RegValue : software\microsoft\internet explorer\main "Enable Browser Extensions"
obj[26]=RegValue : software\microsoft\internet explorer\main "Use Custom Search URL"
obj[27]=RegValue : software\microsoft\internet explorer\main "Search Bar"
ADDESTROYER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[17]=Regkey : S-1-5-21-3995174488-2579519877-2797410178-1005\software\vb and vba program settings\addestroyer
obj[28]=Folder : C:\Program Files\AdDestroyer
obj[30]=File : C:\WINDOWS\system32\PopOops.dll
obj[31]=File : C:\WINDOWS\system32\PopOops2.dll
obj[32]=File : C:\WINDOWS\system32\SWLAD1.dll
obj[33]=File : C:\WINDOWS\system32\SWLAD2.dll
VIRTUALBOUNCER
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[18]=Regkey : S-1-5-21-3995174488-2579519877-2797410178-1005\software\vb and vba program settings\vbouncer
obj[19]=RegValue : software\microsoft\cryptography\services "DistID"
obj[29]=Folder : C:\Program Files\VBouncer
REDIRECTED HOSTFILE ENTRY
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[20]=Hosts file : 69.20.16.183 auto.search.msn.com
obj[21]=Hosts file : 69.20.16.183 search.netscape.com
obj[22]=Hosts file : 69.20.16.183 ieautosearch
Any help would be greatly appreciated. Thanks.