SuMMiT
Topic Starter
my gf has been complaining about poor system performance. she's running avg with all current virus definitions. i ran a full system scan this morn and it found no viruses, but her virus vault shows all sorts of trojans in the past. her c drive has only about half a meg available in it, which she claims is related to this supposed issue. Her hijackthis! log and virus vault report are below. please let me know if you see anything of concern or have any suggestions. Thx much. As always, you guys rock.
Hijackthis! log:
Logfile of HijackThis v1.99.1
Scan saved at 12:27:14 PM, on 9/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
C:\PROGRA~1\xpoint\agent\Xpagent.exe
C:\PROGRA~1\xpoint\EEClient\xpclient.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\xpoint\SAS\jre\bin\javaw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Belkin\Belkin 802.11g Wireless Card Configuration Utility\utility.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Aladdin Systems\StuffIt\stuffit.exe
C:\Documents and Settings\sabrina\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\PROGRA~1\RXTOOL~1\sfcont.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Belkin 802.11g Wireless Card Utility.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.judicial.state.sc.us/CFIDE/classes/CFJava.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\ibmegath.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\PROGRA~1\RXTOOL~1\sfcont.dll
O20 - Winlogon Notify: st3 - C:\WINDOWS\g327120.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\xpoint\pe\pcradmin.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
O23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\xpoint\agent\Xpagent.exe
Her virus vault reads as follows: (sorry about the poor formatting, it the product of a .csv file)
Trojan horse Downloader.Zlob.AOJ C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\UVWB1MRM\xpassman-v3.400[1].exe 8/13/2006 12:20 xpassman-v3.400[1].exe 52.72 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 20:20 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP170\A0045673.dll 1/21/2006 19:31 A0045673.dll 13.5 KB
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\9JBN1XOA\st3m[1].dll 1/21/2006 18:31 st3m[1].dll 68.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:17 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:17 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:17 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:17 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:15 st3.dll 68.5 KB
Trojan horse Dialer.BCR C:\WINDOWS\system32\ccaccess.dll 1/21/2006 17:15 ccaccess.dll 16.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:15 g327120.dll 13.5 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0043988.exe 1/21/2006 17:15 A0043988.exe 34.5 KB
Trojan horse Exploit.Downloader C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\TUKUN9TW\psg[1].anr 1/21/2006 17:15 psg[1].anr 912 bytes
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll 1/21/2006 17:13 st3m[1].dll 68.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:13 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:12 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:12 st3.dll 68.5 KB
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll 1/21/2006 17:12 st3m[1].dll 68.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045208.exe 1/21/2006 17:12 A0045208.exe 3.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:09 st3.dll 68.5 KB
Trojan horse Generic.LCY C:\WINDOWS\system32\oleext.dll 1/21/2006 17:09 oleext.dll 18 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:08 g327120.dll 13.5 KB
Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045207.exe 1/21/2006 17:07 A0045207.exe 3.15 KB
Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045206.exe 1/21/2006 17:07 A0045206.exe 3.15 KB
Trojan horse Downloader.Generic.KWD C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045205.exe 1/21/2006 17:07 A0045205.exe 6.5 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP133\A0044075.exe 1/21/2006 17:07 A0044075.exe 34.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044041.exe 1/21/2006 17:07 A0044041.exe 3.5 KB
Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044040.dll 1/21/2006 17:07 A0044040.dll 18 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044025.exe 1/21/2006 17:07 A0044025.exe 34.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044016.exe 1/21/2006 17:07 A0044016.exe 3.5 KB
Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044015.dll 1/21/2006 17:07 A0044015.dll 18 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q551503.dll 1/21/2006 17:07 q551503.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q387677.dll 1/21/2006 17:07 q387677.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q354209.dll 1/21/2006 17:07 q354209.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q300772.dll 1/21/2006 17:07 q300772.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q298909.dll 1/21/2006 17:06 q298909.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q294102.dll 1/21/2006 17:06 q294102.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q274785.dll 1/21/2006 17:06 q274785.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:04 g327120.dll 13.5 KB
Trojan horse Generic.LAW C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\runapl[1].exe 1/21/2006 16:05 runapl[1].exe 34.5 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\gdnUS250[1].exe 1/21/2006 16:05 gdnUS250[1].exe 13.53 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\K9YN81UZ\gdnUS2175[1].exe 1/21/2006 16:05 gdnUS2175[1].exe 11.27 KB
Trojan horse Generic.LYA C:\WINDOWS\uninstIU.exe 1/21/2006 15:58 uninstIU.exe 3.5 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\32OB79C5\gdnUS2175[2].exe 1/21/2006 15:56 gdnUS2175[2].exe 11.27 KB
Trojan horse Dialer.BCR C:\Documents and Settings\sabrina\Local Settings\Temp\ICD1.tmp\ccaccess.dll 1/21/2006 15:54 ccaccess.dll 16.5 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\okfiopmd.exe 1/21/2006 15:54 okfiopmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\npodnpmd.exe 1/21/2006 15:53 npodnpmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\lfbcnpmd.exe 1/21/2006 15:53 lfbcnpmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\kdkgopmd.exe 1/21/2006 15:53 kdkgopmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\gejmcmmd.exe 1/21/2006 15:53 gejmcmmd.exe 13 KB
Trojan horse Generic.BXY C:\ntdetecd.exe 1/21/2006 15:51 ntdetecd.exe 3.15 KB
Trojan horse Generic.BXY C:\WINDOWS\system32\vmlib.exe 1/21/2006 15:51 vmlib.exe 3.15 KB
Trojan horse Downloader.Generic.KWD C:\WINDOWS\system32\intell32.exe 1/21/2006 15:50 intell32.exe 6.5 KB
Hijackthis! log:
Logfile of HijackThis v1.99.1
Scan saved at 12:27:14 PM, on 9/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
C:\PROGRA~1\xpoint\agent\Xpagent.exe
C:\PROGRA~1\xpoint\EEClient\xpclient.exe
C:\WINDOWS\system32\cmd.exe
C:\PROGRA~1\xpoint\SAS\jre\bin\javaw.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Belkin\Belkin 802.11g Wireless Card Configuration Utility\utility.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Aladdin Systems\StuffIt\stuffit.exe
C:\Documents and Settings\sabrina\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\PROGRA~1\RXTOOL~1\sfcont.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: PeoplePal Toolbar - {A8FB8EB3-183B-4598-924D-86F0E5E37085} - C:\Program Files\PeoplePC\Toolbar\PPCToolbar.dll (file missing)
O4 - HKLM\..\Run: [S3TRAY2] S3Tray2.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "c:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QCTray] C:\PROGRA~1\ThinkPad\CONNEC~1\QCTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Belkin 802.11g Wireless Card Utility.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.judicial.state.sc.us/CFIDE/classes/CFJava.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - file://C:\Program Files\Support.com\Bin\IBMAccessSupport\common\install\ibmegath.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\PROGRA~1\RXTOOL~1\sfcont.dll
O20 - Winlogon Notify: st3 - C:\WINDOWS\g327120.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Xpoint PCRadmin Server (PCRadminServer) - Unknown owner - C:\PROGRA~1\xpoint\pe\pcradmin.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe
O23 - Service: QCONSVC - Unknown owner - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Xpoint Admin Server (XPadminServer) - Unknown owner - C:\PROGRA~1\xpoint\xpadmin\xpadmin.exe
O23 - Service: Xpoint Agent Server (xpAgentServer) - Unknown owner - C:\PROGRA~1\xpoint\agent\Xpagent.exe
Her virus vault reads as follows: (sorry about the poor formatting, it the product of a .csv file)
Trojan horse Downloader.Zlob.AOJ C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\UVWB1MRM\xpassman-v3.400[1].exe 8/13/2006 12:20 xpassman-v3.400[1].exe 52.72 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 20:20 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP170\A0045673.dll 1/21/2006 19:31 A0045673.dll 13.5 KB
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\9JBN1XOA\st3m[1].dll 1/21/2006 18:31 st3m[1].dll 68.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:17 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:17 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:17 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:17 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:15 st3.dll 68.5 KB
Trojan horse Dialer.BCR C:\WINDOWS\system32\ccaccess.dll 1/21/2006 17:15 ccaccess.dll 16.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:15 g327120.dll 13.5 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0043988.exe 1/21/2006 17:15 A0043988.exe 34.5 KB
Trojan horse Exploit.Downloader C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\TUKUN9TW\psg[1].anr 1/21/2006 17:15 psg[1].anr 912 bytes
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll 1/21/2006 17:13 st3m[1].dll 68.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:13 st3.dll 68.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:12 g327120.dll 13.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:12 st3.dll 68.5 KB
Trojan horse Generic.DGK C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\HR3JH5OE\st3m[1].dll 1/21/2006 17:12 st3m[1].dll 68.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045208.exe 1/21/2006 17:12 A0045208.exe 3.5 KB
Trojan horse Generic.DGK C:\WINDOWS\system32\st3.dll 1/21/2006 17:09 st3.dll 68.5 KB
Trojan horse Generic.LCY C:\WINDOWS\system32\oleext.dll 1/21/2006 17:09 oleext.dll 18 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:08 g327120.dll 13.5 KB
Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045207.exe 1/21/2006 17:07 A0045207.exe 3.15 KB
Trojan horse Generic.BXY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045206.exe 1/21/2006 17:07 A0045206.exe 3.15 KB
Trojan horse Downloader.Generic.KWD C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP134\A0045205.exe 1/21/2006 17:07 A0045205.exe 6.5 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP133\A0044075.exe 1/21/2006 17:07 A0044075.exe 34.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044041.exe 1/21/2006 17:07 A0044041.exe 3.5 KB
Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044040.dll 1/21/2006 17:07 A0044040.dll 18 KB
Trojan horse Generic.LAW C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044025.exe 1/21/2006 17:07 A0044025.exe 34.5 KB
Trojan horse Generic.LYA C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044016.exe 1/21/2006 17:07 A0044016.exe 3.5 KB
Trojan horse Generic.LCY C:\System Volume Information\_restore{14157744-4FA2-4CAF-BAFB-72CC49941087}\RP132\A0044015.dll 1/21/2006 17:07 A0044015.dll 18 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q551503.dll 1/21/2006 17:07 q551503.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q387677.dll 1/21/2006 17:07 q387677.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q354209.dll 1/21/2006 17:07 q354209.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q300772.dll 1/21/2006 17:07 q300772.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q298909.dll 1/21/2006 17:06 q298909.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q294102.dll 1/21/2006 17:06 q294102.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\q274785.dll 1/21/2006 17:06 q274785.dll 13.5 KB
Trojan horse Downloader.Generic.IPF C:\WINDOWS\g327120.dll 1/21/2006 17:04 g327120.dll 13.5 KB
Trojan horse Generic.LAW C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\runapl[1].exe 1/21/2006 16:05 runapl[1].exe 34.5 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\RTR7ECT0\gdnUS250[1].exe 1/21/2006 16:05 gdnUS250[1].exe 13.53 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\K9YN81UZ\gdnUS2175[1].exe 1/21/2006 16:05 gdnUS2175[1].exe 11.27 KB
Trojan horse Generic.LYA C:\WINDOWS\uninstIU.exe 1/21/2006 15:58 uninstIU.exe 3.5 KB
Trojan horse Downloader.Generic.NON C:\Documents and Settings\sabrina\Local Settings\Temporary Internet Files\Content.IE5\32OB79C5\gdnUS2175[2].exe 1/21/2006 15:56 gdnUS2175[2].exe 11.27 KB
Trojan horse Dialer.BCR C:\Documents and Settings\sabrina\Local Settings\Temp\ICD1.tmp\ccaccess.dll 1/21/2006 15:54 ccaccess.dll 16.5 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\okfiopmd.exe 1/21/2006 15:54 okfiopmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\npodnpmd.exe 1/21/2006 15:53 npodnpmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\lfbcnpmd.exe 1/21/2006 15:53 lfbcnpmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\kdkgopmd.exe 1/21/2006 15:53 kdkgopmd.exe 13 KB
Trojan horse Dialer.AOZ C:\Documents and Settings\sabrina\Local Settings\Temp\gejmcmmd.exe 1/21/2006 15:53 gejmcmmd.exe 13 KB
Trojan horse Generic.BXY C:\ntdetecd.exe 1/21/2006 15:51 ntdetecd.exe 3.15 KB
Trojan horse Generic.BXY C:\WINDOWS\system32\vmlib.exe 1/21/2006 15:51 vmlib.exe 3.15 KB
Trojan horse Downloader.Generic.KWD C:\WINDOWS\system32\intell32.exe 1/21/2006 15:50 intell32.exe 6.5 KB