Logfile of HijackThis v1.99.1
Scan saved at 7:56:24 PM, on 11/15/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Generic\USB Card Reader Driver v2.2e\FlashIcon.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1126102289\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1126102289\ee\AOLServiceHost.exe
C:\Program Files\Common Files\AOL\1126102289\ee\AOLServiceHost.exe
C:\Documents and Settings\CoyDog\My Documents\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [FlashIcon] C:\Program Files\Generic\USB Card Reader Driver v2.2e\FlashIcon.EXE
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [FNI.WAS5_0001_CP] "C:\Documents and Settings\CoyDog\Desktop\WinAntiSpyware2005Install.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = ?
O4 - Global Startup: WorldAntiSpy.lnk = C:\Program Files\WorldAntiSpy\WorldAntiSpy.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1130969172343
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
(11/15/05 7:39:40 PM) SPSeHjFix started v1.1.2
(11/15/05 7:39:40 PM) OS: WinXP Service Pack 2 (5.1.2600)
(11/15/05 7:39:40 PM) Language: english
(11/15/05 7:39:40 PM) Win-Path: C:\WINDOWS
(11/15/05 7:39:40 PM) System-Path: C:\WINDOWS\system32
(11/15/05 7:39:40 PM) Temp-Path: C:\DOCUME~1\CoyDog\LOCALS~1\Temp\
(11/15/05 7:39:44 PM) Disinfection started
(11/15/05 7:39:44 PM) Bad-Dll(IEP): c:\docume~1\coydog\locals~1\temp\se.dll
(11/15/05 7:39:44 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\kead.dll
(11/15/05 7:39:44 PM) Searchassistant Uninstaller - Keys Deleted
(11/15/05 7:39:44 PM) UBF: 7 - UBB: 0 - UBR: 10
(11/15/05 7:39:44 PM) FilterKey: HKCR\text/html (deleted)
(11/15/05 7:39:44 PM) FilterKey: HKCR\CLSID\{96545D87-C212-4100-AB6C-242829EB7CA7} (deleted)
(11/15/05 7:39:44 PM) FilterKey: HKLM\SOFTWARE\Classes\text/html (error while deleting)
(11/15/05 7:39:44 PM) FilterKey: HKCR\text/plain (deleted)
(11/15/05 7:39:44 PM) FilterKey: HKCR\CLSID\{96545D87-C212-4100-AB6C-242829EB7CA7} (error while deleting)
(11/15/05 7:39:44 PM) FilterKey: HKLM\SOFTWARE\Classes\text/plain (error while deleting)
(11/15/05 7:39:44 PM) BHO-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{11B1993D-D61B-46D3-8030-76CCD659016C} (deleted)
(11/15/05 7:39:44 PM) BHO-Key: HKCR\CLSID\{11B1993D-D61B-46D3-8030-76CCD659016C} (deleted)
(11/15/05 7:39:44 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\CoyDog\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(11/15/05 7:39:44 PM) UBF: 5 - UBB: 0 - UBR: 9
(11/15/05 7:39:44 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\coydog\locals~1\temp\se.dll/space.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\coydog\locals~1\temp\se.dll/space.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(11/15/05 7:39:44 PM) Stealth-String not found
(11/15/05 7:39:44 PM) File added to delete: c:\windows\system32\kead.dll
(11/15/05 7:39:44 PM) File added to delete: c:\docume~1\coydog\locals~1\temp\se.dll
(11/15/05 7:39:44 PM) Reboot
(11/15/05 7:41:03 PM) SPSeHjFix started v1.1.2
(11/15/05 7:41:03 PM) OS: WinXP Service Pack 2 (5.1.2600)
(11/15/05 7:41:03 PM) Language: english
(11/15/05 7:41:03 PM) Win-Path: C:\WINDOWS
(11/15/05 7:41:03 PM) System-Path: C:\WINDOWS\system32
(11/15/05 7:41:03 PM) Temp-Path: C:\DOCUME~1\CoyDog\LOCALS~1\Temp\
(11/15/05 7:50:11 PM) SPSeHjFix started v1.1.2
(11/15/05 7:50:11 PM) OS: WinXP Service Pack 2 (5.1.2600)
(11/15/05 7:50:11 PM) Language: english
(11/15/05 7:50:11 PM) Win-Path: C:\WINDOWS
(11/15/05 7:50:11 PM) System-Path: C:\WINDOWS\system32
(11/15/05 7:50:11 PM) Temp-Path: C:\DOCUME~1\CoyDog\LOCALS~1\Temp\
(11/15/05 7:50:20 PM) Disinfection started
(11/15/05 7:50:20 PM) Bad-Dll(IEP): c:\docume~1\coydog\locals~1\temp\se.dll
(11/15/05 7:50:20 PM) Searchassistant Uninstaller found: regsvr32 /s /u C:\WINDOWS\system32\kead.dll
(11/15/05 7:50:20 PM) Searchassistant Uninstaller - Keys Deleted
(11/15/05 7:50:20 PM) UBF: 5 - UBB: 0 - UBR: 11
(11/15/05 7:50:20 PM) Run-Key: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\sp=rundll32 C:\DOCUME~1\CoyDog\LOCALS~1\Temp\se.dll,DllInstall (deleted)
(11/15/05 7:50:20 PM) UBF: 5 - UBB: 0 - UBR: 10
(11/15/05 7:50:20 PM) Bad IE-pages:
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\coydog\locals~1\temp\se.dll/space.html
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKCU\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Bar: res://c:\docume~1\coydog\locals~1\temp\se.dll/space.html
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Search Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, Start Page: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Main, HomeOldSP: about:blank
deleted: HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant: about:blank
(11/15/05 7:50:20 PM) Stealth-String not found
(11/15/05 7:50:20 PM) File added to delete: c:\windows\system32\kead.dll
(11/15/05 7:50:20 PM) File added to delete: c:\docume~1\coydog\locals~1\temp\se.dll
(11/15/05 7:50:20 PM) Reboot
(11/15/05 7:51:18 PM) SPSeHjFix started v1.1.2
(11/15/05 7:51:18 PM) OS: WinXP Service Pack 2 (5.1.2600)
(11/15/05 7:51:18 PM) Language: english
(11/15/05 7:51:18 PM) Win-Path: C:\WINDOWS
(11/15/05 7:51:18 PM) System-Path: C:\WINDOWS\system32
(11/15/05 7:51:18 PM) Temp-Path: C:\DOCUME~1\CoyDog\LOCALS~1\Temp\
(11/15/05 7:51:57 PM) Disinfection started
(11/15/05 7:51:57 PM) Bad-Dll(IEP): (not found)
(11/15/05 7:51:57 PM) Bad-Dll(IEP) in BHO: (not found)
(11/15/05 7:51:57 PM) UBF: 5 - UBB: 0 - UBR: 10
(11/15/05 7:51:57 PM) UBF: 5 - UBB: 0 - UBR: 10
(11/15/05 7:51:57 PM) Bad IE-pages: (none)
(11/15/05 7:51:57 PM) Stealth-String not found
(11/15/05 7:51:57 PM) Not infected->END
Wow, that's a ton of text! Well, cross-fingers, I'm pretty sure I ran those two programs correctly, and I think they got rid of that dll file. And, yup, IE is working just fine!!! Oh man, thank you so much, is there anything else I should do (run a spyware program or such)? If not, thanks again for the help with my first, and hopefully last, virus.....