gwinslow
Topic Starter
Logfile of HijackThis v1.99.0
Scan saved at 10:16:39 PM, on 1/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\updatetc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\vmss\vmss.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\Temp\WTuninst.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\tmp\hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
= http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://keyword.netscape.com/keyword/%s
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -
{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV
Media\TvmBho.dll
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} -
C:\WINNT\system32\qtbhjwvl.dll
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} -
C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} -
C:\WINNT\system32\ipobxzo.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} -
C:\WINNT\system32\smiehlp.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} -
(no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -
C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: BA Toolbar - {952EC978-4920-4F18-8237-91D69B54C580} -
C:\Program Files\SearchLocate\sidebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI
Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program
Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD
Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program
Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power
Scan\powerscan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint
Manager\ViewMgr.exe
O4 - HKLM\..\Run: [tpcupdater] C:\WINNT\updatetc.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program
Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [function setCookie(name, value) ]
c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire
= new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today =
new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 *
24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60
* 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ]
c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ]
c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ]
c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset +=
search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end
== -1)
O4 - HKLM\..\Run: [end = document.cookie.length ]
c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset,
end)) ] c:\WINNT\System32\return
unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function
mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa]
c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function
FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu]
c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function
exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window
horizontally centered, rou] c:\WINNT\System32\var pos_left =
(screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1
pixel below the bottom of sc] c:\WINNT\System32\var pos_top =
(screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3,
'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL3,
'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run:
c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else
{c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl]
c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function
redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL2,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run: [window.open(URL,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINNT\ARUpdate.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common
Files\Java\bcre.exe"
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\}
O4 - HKLM\..\Run: [ top.location.replace(strTe]
c:\WINNT\System32\ top.location.replace(strTemp);
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe
/remove
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]
"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function
redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe]
c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program
Files\Digital Line Detect\DLG.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program
Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone
Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O8 - Extra context menu item: &AIM Search - res://C:\Program
Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program
Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug -
{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program
Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php…0cfd84064750d9f
f670ca95bb207a82492892b3b9ab0b150d34825d6c1f4faa5632c97c7c30f0d562bb0
995df42c0e856e17f438bb38f5ace6de305:6a2feff70aa50e4b3d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwe…/SmileyCentralI
nitialSetup1.0.0.8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control)
-
http://a840.g.akamai.net/7/840/537/2004061…l.trendmicro.co
m/housecall/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller
Class) -
http://download.zonelabs.com/bin/promotion…ector/WebSWK.ca
b
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan
Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4}
(IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX
Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown -
C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom
Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS
Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. -
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe (file missing)
Scan saved at 10:16:39 PM, on 1/7/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\basfipm.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\bcmwltry.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINNT\system32\PRPCUI.exe
C:\WINNT\System32\DSentry.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINNT\updatetc.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Bcpc\bcpc.exe
C:\WINNT\system32\wsxsvc\wsxsvc.exe
C:\WINNT\system32\vmss\vmss.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINNT\Temp\WTuninst.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\SECRETMAKER\secretmaker.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\tmp\hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL
= http://education.dellnet.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://home.netscape.com/home/winsearch200.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://keyword.netscape.com/keyword/%s
R0 - HKCU\Software\Microsoft\Internet
Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) -
{20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Program Files\TV
Media\TvmBho.dll
O2 - BHO: AcroIEHlprObj Class -
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1FF7E413-A730-AA28-BEFF-1802E32360A5} -
C:\WINNT\system32\qtbhjwvl.dll
O2 - BHO: (no name) - {2592FCDA-FF7C-BD12-D7F9-3F42ADCC6D6F} -
C:\WINNT\system32\wzmtsrwz.dll
O2 - BHO: (no name) - {43891F0B-E811-27BD-8071-66557CD42B6E} -
C:\WINNT\system32\ipobxzo.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeHelper Class - {A491D208-B353-490F-B81A-A8A3DC97042D} -
C:\WINNT\system32\smiehlp.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {4CC0FAF8-6048-421C-9FE2-261A9ECE5F80} -
(no file)
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} -
C:\Program Files\AIM Toolbar\AIMBar.dll
O3 - Toolbar: BA Toolbar - {952EC978-4920-4F18-8237-91D69B54C580} -
C:\Program Files\SearchLocate\sidebar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI
Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program
Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINNT\System32\DSentry.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD
Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [sureshotpopupkiller] "C:\Program
Files\Stop-the-Pop-Up Demo\stopthepop.exe" -minimized
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power
Scan\powerscan.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint
Manager\ViewMgr.exe
O4 - HKLM\..\Run: [tpcupdater] C:\WINNT\updatetc.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program
Files\WildTangent\Apps\CDA\cdaEngine0400.dll",cdaEngineMain
O4 - HKLM\..\Run: [function setCookie(name, value) ]
c:\WINNT\System32\function setCookie(name, value) {
O4 - HKLM\..\Run: [var expire = new Dat] c:\WINNT\System32\var expire
= new Date();
O4 - HKLM\..\Run: [var today = new Dat] c:\WINNT\System32\var today =
new Date();
O4 - HKLM\..\Run: [expire.setTime(today.getTime() + 1000 * 60 * 60 *
24 * 3] c:\WINNT\System32\expire.setTime(today.getTime() + 1000 * 60
* 60 * 24 * 365);
O4 - HKLM\..\Run: [function getCookie(Name) ]
c:\WINNT\System32\function getCookie(Name) {
O4 - HKLM\..\Run: [offset = document.cookie.indexOf(search) ]
c:\WINNT\System32\offset = document.cookie.indexOf(search)
O4 - HKLM\..\Run: [if (offset != -1) { // if cookie exists ]
c:\WINNT\System32\if (offset != -1) { // if cookie exists
O4 - HKLM\..\Run: [offset += search.leng] c:\WINNT\System32\offset +=
search.length;
O4 - HKLM\..\Run: [if (end == -1) ] c:\WINNT\System32\if (end
== -1)
O4 - HKLM\..\Run: [end = document.cookie.length ]
c:\WINNT\System32\end = document.cookie.length
O4 - HKLM\..\Run: [return unescape(document.cookie.substring(offset,
end)) ] c:\WINNT\System32\return
unescape(document.cookie.substring(offset, end))
O4 - HKLM\..\Run: [function mhppo] c:\WINNT\System32\function
mhppop(){
O4 - HKLM\..\Run: [var cookieExist = getCookie(strCookieNa]
c:\WINNT\System32\var cookieExist = getCookie(strCookieName);
O4 - HKLM\..\Run: [function FormFocu] c:\WINNT\System32\function
FormFocus(){
O4 - HKLM\..\Run: [document.frmSearch.KeyWords.focu]
c:\WINNT\System32\document.frmSearch.KeyWords.focus();
O4 - HKLM\..\Run: [flag] c:\WINNT\System32\flag = 1
O4 - HKLM\..\Run: [function exittraff] c:\WINNT\System32\function
exittraffic()
O4 - HKLM\..\Run: [if ((flag ==] c:\WINNT\System32\if ((flag == 1))
O4 - HKLM\..\Run: [var pos_left = (screen.width / 2) -125; // window
horizontally centered, rou] c:\WINNT\System32\var pos_left =
(screen.width / 2) -125; // window horizontally centered, roughly
O4 - HKLM\..\Run: [var pos_top = (screen.height) + 1; // window is 1
pixel below the bottom of sc] c:\WINNT\System32\var pos_top =
(screen.height) + 1; // window is 1 pixel below the bottom of screen
O4 - HKLM\..\Run: [window.open(URL3,
'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL3,
'ncaseWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run:
c:\WINNT\System32\s=screen.width;v=navigator.appName
O4 - HKLM\..\Run: [else {c=screen.pixelDe] c:\WINNT\System32\else
{c=screen.pixelDepth}
O4 - HKLM\..\Run: [j=navigator.javaEnabl]
c:\WINNT\System32\j=navigator.javaEnabled()
O4 - HKLM\..\Run: [NS2] c:\WINNT\System32\NS2Ch=0
O4 - HKLM\..\Run: [if (NS2Ch == ] c:\WINNT\System32\if (NS2Ch == 0) {
O4 - HKLM\..\Run: [function redirec] c:\WINNT\System32\function
redirect(){
O4 - HKLM\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKLM\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKLM\..\Run: [window.open(URL2,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL2,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run: [window.open(URL,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' + pos_t]
c:\WINNT\System32\window.open(URL,
'gatorWin','width=250,height=250,left=' + pos_left + ',top=' +
pos_top);
O4 - HKLM\..\Run: [AdRoarUpdate] C:\WINNT\ARUpdate.exe
O4 - HKLM\..\Run: [Breg] "C:\Program Files\Common
Files\Java\bcre.exe"
O4 - HKLM\..\Run: [BCPC] "C:\Program Files\Bcpc\bcpc.exe"
O4 - HKLM\..\Run: [Dvx] C:\WINNT\system32\wsxsvc\wsxsvc.exe
O4 - HKLM\..\Run: [vmss] C:\WINNT\system32\vmss\vmss.exe
O4 - HKLM\..\Run: [] c:\WINNT\System32\}
O4 - HKLM\..\Run: [ top.location.replace(strTe]
c:\WINNT\System32\ top.location.replace(strTemp);
O4 - HKLM\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone
Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Uninstall_WinTools] C:\WINNT\Temp\WTuninst.exe
/remove
O4 - HKCU\..\Run: [PopUpStopperFreeEdition]
"C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [TV Media] C:\Program Files\TV Media\Tvm.exe
O4 - HKCU\..\Run: [] c:\WINNT\System32\}
O4 - HKCU\..\Run: [function redirec] c:\WINNT\System32\function
redirect(){
O4 - HKCU\..\Run: [var strT] c:\WINNT\System32\var strTemp;
O4 - HKCU\..\Run: [var strP] c:\WINNT\System32\var strPort;
O4 - HKCU\..\Run: [ top.location.replace(strTe]
c:\WINNT\System32\ top.location.replace(strTemp);
O4 - Global Startup: Digital Line Detect.lnk = C:\Program
Files\Digital Line Detect\DLG.exe
O4 - Global Startup: SECRETMAKER.lnk = C:\Program
Files\SECRETMAKER\secretmaker.exe
O4 - Global Startup: zonealarm.lnk = C:\Program Files\Zone
Labs\ZoneAlarm\zonealarm.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O8 - Extra context menu item: &AIM Search - res://C:\Program
Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program
Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Web Rebates - file://C:\Program
Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -
C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug -
{AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program
Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .mid: C:\Program Files\Internet
Explorer\PLUGINS\npqtplugin2.dll
O12 - Plugin for .spop: C:\Program Files\Internet
Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess -
http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Poker -
http://download.games.yahoo.com/games/clients/y/pt1_x.cab
O16 - DPF: Yahoo! Pool 2 -
http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
http://public.windupdates.com/get_file.php…0cfd84064750d9f
f670ca95bb207a82492892b3b9ab0b150d34825d6c1f4faa5632c97c7c30f0d562bb0
995df42c0e856e17f438bb38f5ace6de305:6a2feff70aa50e4b3d9d6f067011f31e
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
http://ak.imgfarm.com/images/nocache/funwe…/SmileyCentralI
nitialSetup1.0.0.8.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control)
-
http://a840.g.akamai.net/7/840/537/2004061…l.trendmicro.co
m/housecall/xscan53.cab
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) -
http://static.topconverting.com/activex/loader2.ocx
O16 - DPF: {99B6E512-3893-4155-9964-8EB8E06099CB} (WebSpyWareKiller
Class) -
http://download.zonelabs.com/bin/promotion…ector/WebSWK.ca
b
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan
Installer Class) -
http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {E0CE16CB-741C-4B24-8D04-A817856E07F4}
(IObjSafety.DemoCtl) - http://cabs.media-motor.net/cabs/alien.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX
Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain =
STUDENT.framingham.edu
O23 - Service: Ati HotKey Poller - Unknown -
C:\WINNT\System32\Ati2evxx.exe
O23 - Service: Broadcom ASF IP monitoring service v3.0.1 - Broadcom
Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS
Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. -
C:\WINNT\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown - C:\WINNT\System32\WLTRYSVC.EXE
C:\WINNT\System32\bcmwltry.exe (file missing)