Jcatsmom
Topic Starter
A friend asked me to check out a computer that is often locking up and runs CD's at the wrong speed. It has very few documents or programs on it. I did some preliminary checks and it is a mess- Windows XP SP1!, run on the internet a few years ago with neither firewall nor virus protection. The Lavasoft defs are more than 900 days old. I ran AVG Anti-Spyware- scan only. It shows over 200 infections including worm Welchia.b, multiple downloaders, backdoors, trojans, Rootkit.Agent.O, and something suspicious in the trusted zone.
My friend is searching for her installation disks, in case we take the wipe option. I am concerned that it could have a boot sector virus and would like guidance in the quickest, easiest way to heal this sick machine. I am attaching my Hijackthis log and AVG log. Thank you for your help.-Jcatsmom
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:06 AM, on 2/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\aim.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\lsass.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\system12.exe
C:\windows\adtech2005.exe
C:\WINDOWS\System32\Lcuninst.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Laura Whipple\Desktop\computer tools\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Microsoft Windows 128bit Subsystem] C:\WINDOWS\System32\system12.exe
O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe
O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe
O4 - HKLM\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKUS\S-1-5-18\..\Run: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [kquz] C:\PROGRA~1\COMMON~1\kquz\kquzm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows Processe Manager] mspn32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\p4r40e9qeh.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
–
End of file - 4439 bytes
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 11:27:44 AM 2/26/2008
+ Scan result:
C:\Documents and Settings\Laura Whipple\Local Settings\Temp\180sainstaller.exe/clientax.dll -> Adware.180Solutions : Ignored.
C:\WINDOWS\Temp\180sainstallernu.exe/clientax.dll -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller.1 -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Adware.180Solutions : Ignored.
C:\Program Files\Aprps -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\AI_22-08-2005.log -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.exe -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ProxyStub.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\WinGenerics.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ace.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\data.bin -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\libexpat.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\uninstaller.exe -> Adware.Apropos : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\thin-143-1-x-x[1].exe -> Adware.BetterInternet : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049309.exe -> Adware.CommAd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049314.DLL -> Adware.CommAd : Ignored.
HKLM\SOFTWARE\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update\actalert.exe -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-21-329068152-2111687655-1957994488-1004\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\installer[1].exe -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0000.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041299.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048304.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049318.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0050319.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\HZF_INST.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\SELSRV32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\anptif.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\csb.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dirgres.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dlound.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\drsapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\en22l1fo1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl2l13o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl6l13s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ennml1511.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp2l17o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp6l17s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ess.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\g4jo0e13eh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\gctuname.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i6lolg3316.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iGshlpr.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iLsrecst.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iketmib1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j0j6la1s1d.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0080adued080.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0js0a17ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kcdsf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdcz2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kidtuf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kt2ul7f91.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ktdhela2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l0j80a1ued.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4p20e7oeh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4r00e9meh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ljazutil.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\maisip.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mbd32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mewsock.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mfpmspsv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhcpx32r.dLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\miwmdmsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mkconf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\moacm32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mviseq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mxmefilt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nMlanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nalanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ndmarta.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nginstnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nirsja.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nmxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nnprint.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nstlogon.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nutui0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nuxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nyptools.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o0480ahued480.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\oibc16gt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p24ulch91f4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pbwrprof.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pcrfproc.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pih.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\puspl.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q668lgju16o8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rLssapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rbcdll.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rehx32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rvchost.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rycns4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sfbcsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sqtupapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sumapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sximgvw.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sydpsrv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\szc_os.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\t48u0el9ehq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\tapmonui.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ukdmxfrm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\vtmdbg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wfninet.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wghatm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wpwfaxui.dll -> Adware.Look2Me : Ignored.
C:\installer.exe -> Adware.Look2Me : Ignored.
[1128] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
[1548] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\seeve[1].exe -> Adware.MediaMotor : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\mm63[1].ocx -> Adware.MediaMotor : Ignored.
C:\WINDOWS\mm63.ocx -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl\Clsid -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Ignored.
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Ignored.
HKLM\SOFTWARE\VGroup\SAHAgent -> Adware.SAHA : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temp\1CCPRAB8.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\bundle_mediamotor1004[1].exe -> Adware.Sahat : Ignored.
C:\WINDOWS\Temp\9JIK1H9M.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\drsmartload[1].exe -> Adware.SmartLoad : Ignored.
C:\drsmartload1.exe -> Adware.SmartLoad : Ignored.
C:\Program Files\Common Files\kquz\kquzd\kquzc.dll -> Adware.TargetServer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Ignored.
C:\Program Files\TheSearchAccelerator -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\INSTALL.LOG -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\IUCmore.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UNWISE.EXE -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\logo.ico -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\toolbar.cfg -> Adware.UCmore : Ignored.
C:\UCmore - The Search Accelerator\How To Uninstall.lnk -> Adware.Ucmore : Ignored.
C:\UCmore - The Search Accelerator\UCmore Tour.lnk -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/empty_00000001 -> Adware.Ucmore : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCmore - The Search Accelerator -> Adware.UCmore : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\41UBCD2P\iesetup6b[1].exe -> Adware.WinAD : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\69IBC3CN\iesetup6a[1].exe -> Adware.WinAD : Ignored.
C:\ad.exe -> Adware.WinAD : Ignored.
C:\ada.exe -> Adware.WinAD : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\unstall[1].exe -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent.1 -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CLSID -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CurVer -> Adware.Zango : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049310.exe -> Backdoor.Codbot.al : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049315.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP1964 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP308 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\mspn32.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\eraseme_50661.exe -> Backdoor.Rbot.aad : Ignored.
C:\WINDOWS\system32\TFTP2256 -> Backdoor.Rbot.adf : Ignored.
C:\WINDOWS\system32\TFTP1128 -> Backdoor.Rbot.c : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049308.exe -> Backdoor.SdBot.xd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049311.exe -> Backdoor.SdBot.xd : Ignored.
C:\WINDOWS\system32\eraseme_46480.exe -> Backdoor.SdBot.xd : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\drsmartload106a[1].exe -> Downloader.Adload.j : Ignored.
C:\dolrz.exe -> Downloader.Adload.j : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temporary Internet Files\Content.IE5\WHGD05YV\actalert[1].exe -> Downloader.Dyfuca.dp : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\optimize[1].exe -> Downloader.Dyfuca.ei : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049312.exe -> Downloader.Dyfuca.ei : Ignored.
C:\WINDOWS\optimize.exe -> Downloader.Dyfuca.ei : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\xtc[1].exe -> Downloader.Small.aqt : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stubinstaller6282[1].exe -> Downloader.Small.asf : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\mte3ndi6odoxng[1].exe -> Downloader.Small.buy : Ignored.
C:\mte3ndi6odoxng.exe -> Downloader.Small.buy : Ignored.
C:\Program Files\Common Files\kquz\kquzp.exe -> Downloader.TSUpdate.f : Ignored.
C:\Program Files\Common Files\kquz\kquzd\vocabulary -> Downloader.TSUpdate.j : Ignored.
C:\Program Files\Common Files\kquz\kquza.exe -> Downloader.TSUpdate.l : Ignored.
C:\Program Files\Common Files\kquz\kquzm.exe -> Downloader.TSUpdate.n : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stub_113_4_0_4_0[1].exe -> Downloader.TSUpdate.o : Ignored.
C:\stub_113_4_0_4_0.exe -> Downloader.TSUpdate.o : Ignored.
C:\Program Files\Common Files\kquz\kquzl.exe -> Downloader.TSUpdate.p : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[1].exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[2].exe -> Downloader.VB.jl : Ignored.
C:\mmxmetal.exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\timessquare[1].exe -> Hijacker.StartPage.aw : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049323.exe -> Hijacker.StartPage.aw : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[1].exe -> Proxy.Ranky : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[2].exe -> Proxy.Ranky : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049317.EXE -> Proxy.Ranky : Ignored.
C:\prox.exe -> Proxy.Ranky : Ignored.
C:\FOUND.005\FILE0003.CHK -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041303.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0042302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0043302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0044302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0045302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0046302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0047302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048308.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049307.sys -> Rootkit.Agent.o : Ignored.
C:\WINDOWS\system32\rdriv.sys -> Rootkit.Agent.o : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura [removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][4].txt -> TrackingCookie.Msn : Ignored.
D:\Documents and Settings\laura whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Shopathomeselect : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\contextplus[1].exe -> Trojan.Crypt.t : Ignored.
C:\contextplus.exe -> Trojan.Crypt.t : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\teller2[1].htm -> Trojan.Small : Ignored.
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\n3IYwAH0pZ1DwJ1Ptk.vbs -> Trojan.Small : Ignored.
C:\WINDOWS\teller2.chk -> Trojan.Small : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\adtech2005[1].exe -> Trojan.VB.afn : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049316.exe -> Trojan.VB.afn : Ignored.
C:\WINDOWS\system32\drivers\svchost.exe -> Worm.Welchia.b : Ignored.
::Report end
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:06 AM, on 2/16/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\aim.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
C:\WINDOWS\System32\javascript.exe
C:\WINDOWS\lsass.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Internet Optimizer\optimize.exe
C:\WINDOWS\System32\system12.exe
C:\windows\adtech2005.exe
C:\WINDOWS\System32\Lcuninst.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Laura Whipple\Desktop\computer tools\HiJackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
O3 - Toolbar: &Radio; - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Internet Optimizer] "C:\Program Files\Internet Optimizer\optimize.exe"
O4 - HKLM\..\Run: [Microsoft Windows 128bit Subsystem] C:\WINDOWS\System32\system12.exe
O4 - HKLM\..\Run: [timessquare] C:\windows\timessquare.exe
O4 - HKLM\..\Run: [adtech2005] C:\windows\adtech2005.exe
O4 - HKLM\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKLM\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunServices: [Microsoft Windows Update XP64] Lcuninst.exe
O4 - HKUS\S-1-5-18\..\Run: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [kquz] C:\PROGRA~1\COMMON~1\kquz\kquzm.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Microsoft Windows Update XP64] Lcuninst.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Windows Processe Manager] mspn32.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunServices: [Windows Processe Manager] mspn32.exe (User 'Default user')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O20 - Winlogon Notify: DateTime - C:\WINDOWS\system32\p4r40e9qeh.dll
O23 - Service: AOL Instant Messanger (AIM) - Unknown owner - C:\WINDOWS\aim.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\command.exe
O23 - Service: Enables Javascript Support (Javascript) - Unknown owner - C:\WINDOWS\System32\javascript.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\lsass.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
–
End of file - 4439 bytes
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 11:27:44 AM 2/26/2008
+ Scan result:
C:\Documents and Settings\Laura Whipple\Local Settings\Temp\180sainstaller.exe/clientax.dll -> Adware.180Solutions : Ignored.
C:\WINDOWS\Temp\180sainstallernu.exe/clientax.dll -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller.1 -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CLSID -> Adware.180Solutions : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.ClientInstaller\CurVer -> Adware.180Solutions : Ignored.
C:\Program Files\Aprps -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\AI_22-08-2005.log -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\CxtPls.exe -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ProxyStub.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\WinGenerics.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\ace.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\atl.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\data.bin -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\libexpat.dll -> Adware.Apropos : Ignored.
C:\Program Files\Aprps\uninstaller.exe -> Adware.Apropos : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\thin-143-1-x-x[1].exe -> Adware.BetterInternet : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049309.exe -> Adware.CommAd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049314.DLL -> Adware.CommAd : Ignored.
HKLM\SOFTWARE\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKLM\SOFTWARE\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\.DEFAULT\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator -> Adware.EffectiveBrandToolbar : Ignored.
HKU\S-1-5-18\Software\Effective-i\TheSearchAccelerator\IE5 -> Adware.EffectiveBrandToolbar : Ignored.
C:\Program Files\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update -> Adware.InternetOptimizer : Ignored.
C:\Program Files\Internet Optimizer\update\actalert.exe -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Avenue Media\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Optimizer -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Kapabout -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKLM\SOFTWARE\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\.DEFAULT\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-18\Software\Policies\Avenue Media -> Adware.InternetOptimizer : Ignored.
HKU\S-1-5-21-329068152-2111687655-1957994488-1004\Software\Avenue Media -> Adware.InternetOptimizer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\installer[1].exe -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.005\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.006\FILE0002.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0000.CHK -> Adware.Look2Me : Ignored.
C:\FOUND.008\FILE0001.CHK -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041299.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048304.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049318.dll -> Adware.Look2Me : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0050319.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\HZF_INST.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\SELSRV32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\anptif.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\csb.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dirgres.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\dlound.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\drsapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\en22l1fo1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl2l13o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enl6l13s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ennml1511.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp2l17o1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\enp6l17s1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ess.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\g4jo0e13eh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\gctuname.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\i6lolg3316.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iGshlpr.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iLsrecst.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\iketmib1.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\j0j6la1s1d.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0080adued080.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\k0js0a17ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kcdsf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kfdcz2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kidtuf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\kt2ul7f91.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ktdhela2.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l0j80a1ued.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4p20e7oeh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\l4r00e9meh.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ljazutil.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\maisip.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mbd32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mewsock.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mfpmspsv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mhcpx32r.dLL -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\miwmdmsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mkconf.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\moacm32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mviseq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\mxmefilt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nMlanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nalanman.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ndmarta.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nginstnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nirsja.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nmxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nnprint.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nstlogon.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nutui0.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nuxpnt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\nyptools.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\o0480ahued480.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\oibc16gt.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\p24ulch91f4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pbwrprof.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pcrfproc.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\pih.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\puspl.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q0rq0a95ed.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\q668lgju16o8.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rLssapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rbcdll.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rehx32.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rvchost.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\rycns4.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sfbcsp.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sqtupapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sumapi.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sximgvw.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\sydpsrv.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\szc_os.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\t48u0el9ehq.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\tapmonui.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\ukdmxfrm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\vtmdbg.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wfninet.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wghatm.dll -> Adware.Look2Me : Ignored.
C:\WINDOWS\system32\wpwfaxui.dll -> Adware.Look2Me : Ignored.
C:\installer.exe -> Adware.Look2Me : Ignored.
[1128] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
[1548] C:\WINDOWS\system32\rwgwizc.dll -> Adware.Look2Me : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\seeve[1].exe -> Adware.MediaMotor : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\mm63[1].ocx -> Adware.MediaMotor : Ignored.
C:\WINDOWS\mm63.ocx -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Classes\IObjSafety.DemoCtl\Clsid -> Adware.MediaMotor : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\DyFuCA -> Adware.MoneyTree : Ignored.
HKLM\SOFTWARE\VGroup -> Adware.SAHA : Ignored.
HKLM\SOFTWARE\VGroup\SAHAgent -> Adware.SAHA : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temp\1CCPRAB8.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\bundle_mediamotor1004[1].exe -> Adware.Sahat : Ignored.
C:\WINDOWS\Temp\9JIK1H9M.dll -> Adware.Sahat : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\drsmartload[1].exe -> Adware.SmartLoad : Ignored.
C:\drsmartload1.exe -> Adware.SmartLoad : Ignored.
C:\Program Files\Common Files\kquz\kquzd\kquzc.dll -> Adware.TargetServer : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\ucmoreiex[1].exe/empty_00000001 -> Adware.Ucmore : Ignored.
C:\Program Files\TheSearchAccelerator -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\INSTALL.LOG -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\IUCmore.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UCMTSAIE.dll -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\UNWISE.EXE -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\logo.ico -> Adware.UCmore : Ignored.
C:\Program Files\TheSearchAccelerator\toolbar.cfg -> Adware.UCmore : Ignored.
C:\UCmore - The Search Accelerator\How To Uninstall.lnk -> Adware.Ucmore : Ignored.
C:\UCmore - The Search Accelerator\UCmore Tour.lnk -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Ignored.
C:\ucmoreiex.exe/empty_00000001 -> Adware.Ucmore : Ignored.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UCmore - The Search Accelerator -> Adware.UCmore : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\41UBCD2P\iesetup6b[1].exe -> Adware.WinAD : Ignored.
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\69IBC3CN\iesetup6a[1].exe -> Adware.WinAD : Ignored.
C:\ad.exe -> Adware.WinAD : Ignored.
C:\ada.exe -> Adware.WinAD : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\unstall[1].exe -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent.1 -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CLSID -> Adware.Zango : Ignored.
HKLM\SOFTWARE\Classes\ClientAX.RequiredComponent\CurVer -> Adware.Zango : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049310.exe -> Backdoor.Codbot.al : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049315.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP1964 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\TFTP308 -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\mspn32.exe -> Backdoor.Rbot : Ignored.
C:\WINDOWS\system32\eraseme_50661.exe -> Backdoor.Rbot.aad : Ignored.
C:\WINDOWS\system32\TFTP2256 -> Backdoor.Rbot.adf : Ignored.
C:\WINDOWS\system32\TFTP1128 -> Backdoor.Rbot.c : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049308.exe -> Backdoor.SdBot.xd : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049311.exe -> Backdoor.SdBot.xd : Ignored.
C:\WINDOWS\system32\eraseme_46480.exe -> Backdoor.SdBot.xd : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\drsmartload106a[1].exe -> Downloader.Adload.j : Ignored.
C:\dolrz.exe -> Downloader.Adload.j : Ignored.
C:\Documents and Settings\Laura Whipple\Local Settings\Temporary Internet Files\Content.IE5\WHGD05YV\actalert[1].exe -> Downloader.Dyfuca.dp : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\optimize[1].exe -> Downloader.Dyfuca.ei : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049312.exe -> Downloader.Dyfuca.ei : Ignored.
C:\WINDOWS\optimize.exe -> Downloader.Dyfuca.ei : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\xtc[1].exe -> Downloader.Small.aqt : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stubinstaller6282[1].exe -> Downloader.Small.asf : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\mte3ndi6odoxng[1].exe -> Downloader.Small.buy : Ignored.
C:\mte3ndi6odoxng.exe -> Downloader.Small.buy : Ignored.
C:\Program Files\Common Files\kquz\kquzp.exe -> Downloader.TSUpdate.f : Ignored.
C:\Program Files\Common Files\kquz\kquzd\vocabulary -> Downloader.TSUpdate.j : Ignored.
C:\Program Files\Common Files\kquz\kquza.exe -> Downloader.TSUpdate.l : Ignored.
C:\Program Files\Common Files\kquz\kquzm.exe -> Downloader.TSUpdate.n : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\stub_113_4_0_4_0[1].exe -> Downloader.TSUpdate.o : Ignored.
C:\stub_113_4_0_4_0.exe -> Downloader.TSUpdate.o : Ignored.
C:\Program Files\Common Files\kquz\kquzl.exe -> Downloader.TSUpdate.p : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[1].exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\mmxmetal[2].exe -> Downloader.VB.jl : Ignored.
C:\mmxmetal.exe -> Downloader.VB.jl : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\timessquare[1].exe -> Hijacker.StartPage.aw : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049323.exe -> Hijacker.StartPage.aw : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[1].exe -> Proxy.Ranky : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\KV410ZAL\proxi[2].exe -> Proxy.Ranky : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049317.EXE -> Proxy.Ranky : Ignored.
C:\prox.exe -> Proxy.Ranky : Ignored.
C:\FOUND.005\FILE0003.CHK -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0041303.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0042302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0043302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0044302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0045302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0046302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0047302.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048302.sys -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0048308.SYS -> Rootkit.Agent.o : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049307.sys -> Rootkit.Agent.o : Ignored.
C:\WINDOWS\system32\rdriv.sys -> Rootkit.Agent.o : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura whipple@advertising[2].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@doubleclick[2].txt -> TrackingCookie.Doubleclick : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura [removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"]whipple@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][1].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\Laura Whipple\Cookies\laura .txt"][removed][4].txt -> TrackingCookie.Msn : Ignored.
D:\Documents and Settings\laura whipple\Cookies\laura .txt"][removed][2].txt -> TrackingCookie.Msn : Ignored.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Shopathomeselect : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\OLYN4TEZ\contextplus[1].exe -> Trojan.Crypt.t : Ignored.
C:\contextplus.exe -> Trojan.Crypt.t : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\2H4XCNC9\teller2[1].htm -> Trojan.Small : Ignored.
C:\WINDOWS\TGF1cmEgV2hpcHBsZQ\n3IYwAH0pZ1DwJ1Ptk.vbs -> Trojan.Small : Ignored.
C:\WINDOWS\teller2.chk -> Trojan.Small : Ignored.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\W5SLEJ0L\adtech2005[1].exe -> Trojan.VB.afn : Ignored.
C:\System Volume Information\_restore{CBCFA597-27DB-49B6-B757-8C3C08D05636}\RP93\A0049316.exe -> Trojan.VB.afn : Ignored.
C:\WINDOWS\system32\drivers\svchost.exe -> Worm.Welchia.b : Ignored.
::Report end