klois
Topic Starter
There seems to be a lot of different things wrong. My computer seems to be going a lil haywire, and I was hoping someone could help. I've done Ad-aware, Spybot, AVG, and the ATF Cleaner. Here are the logs, and I can be more descriptive of what is happening after someone has posted. Thanks.
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 5:00:28 AM 3/18/2007
+ Scan result:
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047306.exe -> Adware.DownloadWare : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047312.exe -> Adware.Exact : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047313.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047330.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047304.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047318.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047307.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047319.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP466\A0047719.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0060012.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047299.exe -> Backdoor.Delf.avh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047300.exe -> Backdoor.Delf.avh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047317.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047321.exe -> Downloader.Agent.aef : Cleaned with backup (quarantined).
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe1174110493 -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046110.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046111.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046112.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046113.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046114.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046115.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046167.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047267.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047961.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047962.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047963.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047965.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047966.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047971.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047974.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047978.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047273.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047298.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047305.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047316.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047324.exe -> Downloader.Small.cpt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047320.exe -> Downloader.Small.crd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047323.dll -> Downloader.Small.crd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047309.exe -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047322.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047325.exe -> Downloader.Small.dam : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047271.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047315.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047326.exe -> Downloader.Small.dzd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047310.dll -> Downloader.Small.dzf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047302.exe -> Dropper.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047308.exe -> Dropper.Small.atw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP453\A0043847.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP454\A0043870.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP455\A0044794.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP456\A0044804.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP456\A0045794.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP457\A0045796.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045805.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045820.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045853.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP459\A0045879.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP459\A0045889.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047977.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047329.exe -> Proxy.Dlena.ax : Cleaned with backup (quarantined).
C:\WINDOWS\system32\koos.exe -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kprof -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
C:\WINDOWS\system32\poof -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
[224] C:\Documents and Settings\All Users\Documents\Settings\partnership.dll -> Proxy.Xorpix.bc : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\ip6fw.sys -> Rootkit.Agent.dp : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Gary Keipper\Application Data\Mozilla\Firefox\Profiles\r77q3dwm.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.12:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Jeremy Keipper\Cookies\jeremy keipper@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.37:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.38:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Jeremy Keipper\Cookies\jeremy [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054011.dll -> Trojan.Agent.afg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP468\A0049009.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054012.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054013.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\update2.exe -> Trojan.Agent.bou : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047328.exe -> Trojan.Agent.oh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047301.dll -> Trojan.LuckyBar888.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047303.dll -> Trojan.LuckyBar888.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047311.sys -> Trojan.PdPinch.bs : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047314.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047331.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047327.exe -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047269.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047270.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047272.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047332.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 5:20:10 AM, on 3/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
C:\Documents and Settings\Jeremy Keipper\ie_updater.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\Bit Comet\BitComet\tools\BitCometBHO_1.1.2.7.dll (file missing)
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {946a18ee-f66c-4631-8f24-388828de2e45} - C:\WINDOWS\system32\audctm.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {B6F1A4CB-DADD-4D0C-BDFC-E945647302C1} - c:\system.dll (file missing)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\tmp24.tmp.dll (file missing)
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "G:\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\nnonnl.dll",setvm
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! GoStop - http://download.games.yahoo.com/games/clients/y/gst1_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt0_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: audctm - C:\WINDOWS\SYSTEM32\audctm.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documents\Settings\partnership.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ieupdater21 (Microsoft IEUpdater21) - Unknown owner - C:\Documents and Settings\Jeremy Keipper\ie_updater.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 5:00:28 AM 3/18/2007
+ Scan result:
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047306.exe -> Adware.DownloadWare : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047312.exe -> Adware.Exact : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047313.exe -> Adware.MDH : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047330.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047304.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047318.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047307.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047319.dll -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP466\A0047719.exe -> Adware.WinFixer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0060012.sys -> Backdoor.Bulknet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047299.exe -> Backdoor.Delf.avh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047300.exe -> Backdoor.Delf.avh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047317.exe -> Dialer.GBDialer.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047321.exe -> Downloader.Agent.aef : Cleaned with backup (quarantined).
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe1174110493 -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046110.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046111.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046112.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046113.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046114.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046115.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP461\A0046167.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047267.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047961.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047962.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047963.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047965.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047966.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047971.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047974.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047978.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047273.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047298.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047305.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047316.exe -> Downloader.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047324.exe -> Downloader.Small.cpt : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047320.exe -> Downloader.Small.crd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047323.dll -> Downloader.Small.crd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047309.exe -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047322.dll -> Downloader.Small.cyn : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047325.exe -> Downloader.Small.dam : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047271.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047315.exe -> Downloader.Small.dgk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047326.exe -> Downloader.Small.dzd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047310.dll -> Downloader.Small.dzf : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047302.exe -> Dropper.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047308.exe -> Dropper.Small.atw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP453\A0043847.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP454\A0043870.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP455\A0044794.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP456\A0044804.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP456\A0045794.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP457\A0045796.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045805.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045820.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP458\A0045853.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP459\A0045879.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP459\A0045889.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP467\A0047977.dll -> Proxy.Agent.jk : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047329.exe -> Proxy.Dlena.ax : Cleaned with backup (quarantined).
C:\WINDOWS\system32\koos.exe -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kprof -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
C:\WINDOWS\system32\poof -> Proxy.Wopla.ag : Cleaned with backup (quarantined).
[224] C:\Documents and Settings\All Users\Documents\Settings\partnership.dll -> Proxy.Xorpix.bc : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\ip6fw.sys -> Rootkit.Agent.dp : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\Gary Keipper\Application Data\Mozilla\Firefox\Profiles\r77q3dwm.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.12:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Jeremy Keipper\Cookies\jeremy keipper@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.37:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Real : Cleaned.
:mozilla.38:C:\Documents and Settings\Brad Keipper\Application Data\Mozilla\Firefox\Profiles\ajbeth58.default\cookies.txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Jeremy Keipper\Cookies\jeremy [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054011.dll -> Trojan.Agent.afg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP468\A0049009.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054012.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP469\A0054013.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\system32\update2.exe -> Trojan.Agent.bou : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047328.exe -> Trojan.Agent.oh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047301.dll -> Trojan.LuckyBar888.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047303.dll -> Trojan.LuckyBar888.a : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047311.sys -> Trojan.PdPinch.bs : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047314.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047331.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047327.exe -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047269.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047270.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047272.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{E218C18C-C065-4AF6-827D-E8070CA783D2}\RP462\A0047332.exe -> Worm.Nuwar.i : Cleaned with backup (quarantined).
::Report end
Logfile of HijackThis v1.99.1
Scan saved at 5:20:10 AM, on 3/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
C:\Documents and Settings\Jeremy Keipper\ie_updater.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R3 - URLSearchHook: URLSearchHook Class - {37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8} - C:\Program Files\NZSearch\SearchEnh1.dll
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - G:\Bit Comet\BitComet\tools\BitCometBHO_1.1.2.7.dll (file missing)
O2 - BHO: Popup-Blocker Class - {52706EF7-D7A2-49AD-A615-E903858CF284} - C:\Program Files\NetZero\qsacc\x1IEBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {946a18ee-f66c-4631-8f24-388828de2e45} - C:\WINDOWS\system32\audctm.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: (no name) - {B6F1A4CB-DADD-4D0C-BDFC-E945647302C1} - c:\system.dll (file missing)
O2 - BHO: (no name) - {D38439EC-4A7F-42b4-90C2-D810D7778FDD} - C:\WINDOWS\system32\tmp24.tmp.dll (file missing)
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\Toolbar.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\toolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [DAEMON Tools-1033] "G:\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\nnonnl.dll",setvm
O4 - HKLM\..\Run: [Lexmark_X79-55] C:\WINDOWS\system32\lsasss.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [DJSNetCN] C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://G:\Bit Comet\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Display All Images with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/228
O8 - Extra context menu item: Display Image with Full Quality - res://C:\Program Files\NetZero\qsacc\appres.dll/227
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - AutorunsDisabled - (no file)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Checkers - http://download.games.yahoo.com/games/clients/y/kt4_x.cab
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Dominoes - http://download.games.yahoo.com/games/clients/y/dot8_x.cab
O16 - DPF: Yahoo! Euchre - http://download.games.yahoo.com/games/clients/y/et1_x.cab
O16 - DPF: Yahoo! Fleet - http://download.games.yahoo.com/games/clients/y/fltt3_x.cab
O16 - DPF: Yahoo! GoStop - http://download.games.yahoo.com/games/clients/y/gst1_x.cab
O16 - DPF: Yahoo! Literati - http://download.games.yahoo.com/games/clients/y/tt0_x.cab
O16 - DPF: Yahoo! Poker - http://download.games.yahoo.com/games/clients/y/pt0_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.napster.com/client/isetup.cab
O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/…utocomplete.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/popc…aploader_v6.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: A3dxq - C:\WINDOWS\system32\a3dxq.dll
O20 - Winlogon Notify: audctm - C:\WINDOWS\SYSTEM32\audctm.dll
O20 - Winlogon Notify: AutorunsDisabled - C:\WINDOWS\
O20 - Winlogon Notify: partnershipreg - C:\Documents and Settings\All Users\Documents\Settings\partnership.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Licensing Detect Internet Connection (DJSNETCN) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\DJSNETCN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: ieupdater21 (Microsoft IEUpdater21) - Unknown owner - C:\Documents and Settings\Jeremy Keipper\ie_updater.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe