TheTechGuide Forum
General Category => Tech Clinic => Topic started by: Zampý on October 03, 2005, 01:39:23 PM
-
I found this worm (Win32.P2P-Worm.Alcan.a) during my Ad-aware scan, also when I start Windows, Norman Antivirus tells me that it has found: W32/spybot.UNQ worm from my drive. I delete it, but every time when I start windows: it comes again. Could somebody tell me how to get rid off thease worms. What should I do??
/unsure.gif\' class=\'bbc_emoticon\' alt=\':unsure:\' />
Here is my logfile:
Logfile of HijackThis v1.99.1
Scan saved at 21:26:34, on 3.10.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
C:\Norman\bin\ZANDA.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\NORMAN\Nvc\BIN\nvcoas.exe
C:\Norman\bin\NJEEVES.EXE
C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
C:\NORMAN\Nvc\BIN\nipsvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\Norman\bin\ZLH.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Logitech\MediaLife\MediaLifeService.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\MessengerPlus\MsgPlus.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\winsupdater\winsupdater.exe
C:\Norman\Nvc\BIN\NIP.EXE
C:\Norman\Nvc\bin\cclaw.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Norman\Npf\BIN\npfmsg2.exe
C:\Program Files\UltimateZip\uzqkst.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Omistaja\Työpöytä\Hijack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fi/0SEFIFI/SAOS01 (http://\"http://g.msn.fi/0SEFIFI/SAOS01\")
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00C9D850-244D-10E1-B3C1-20805E499D95} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\fi\msntb.dll
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Norman ZANDA] C:\Norman\bin\ZLH.EXE /LOAD /SPLASH
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Logitech\MediaLife\MediaLifeService.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus\MsgPlus.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [winsupdater] C:\Program Files\winsupdater\winsupdater.exe /auto
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: UltimateZip Quick Start.lnk = C:\Program Files\UltimateZip\uzqkst.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: Vie Microsoft E&xceliin - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Oheistiedot - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab\")
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15012/CTSUEng.cab (http://\"http://www.creative.com/su/ocx/15012/CTSUEng.cab\")
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 (http://\"http://go.microsoft.com/fwlink/?linkid=39204\")
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab\")
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab\")
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion...ctor/WebAAS.cab (http://\"http://download.zonelabs.com/bin/promotions/spywaredetector/WebAAS.cab\")
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab (http://\"http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab\")
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab\")
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/Chess.cab31267.cab\")
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15012/CTPID.cab (http://\"http://www.creative.com/su/ocx/15012/CTPID.cab\")
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab\")
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\NORMAN\Nvc\BIN\nipsvc.exe
O23 - Service: Norman NJeeves - Unknown owner - C:\Norman\bin\NJEEVES.EXE
O23 - Service: Norman Type-R - Unknown owner - C:\NORMAN\Nvc\BIN\NPFSVICE.EXE
O23 - Service: Norman ZANDA - Unknown owner - C:\Norman\bin\ZANDA.EXE
O23 - Service: Norman Virus Control on-access component (nvcoas) - Norman ASA - C:\NORMAN\Nvc\BIN\nvcoas.exe
O23 - Service: Norman Virus Control Scheduler (NVCScheduler) - Norman Data Defense Systems - C:\NORMAN\Nvc\BIN\NVCSCHED.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
-
Hi Zampý and Welcome to TheTechGuide!
This has become a real pesky bug to deal with as of late,so please be patient with me!
Download WinPFind:
WinPFind (http://\"http://www.bleepingcomputer.com/files/winpfind.php\")
Right Click the Zip Folder and Select "Extract All"
Don't use it yet!
Download and unzip BFUzip from HERE (http://\"http://computercops.biz/zx/Merijn/bfu.zip\")
Right Click the Zip folder and select "Extract All"
Locate and double click BFU.exe
Now locate and click the Greenish Blue globe with the chord plugged into it!
When the next small window pops up-> Copy&Paste this URL into it and click OK!
http://webpages.charter.net/cretemonster/p2pnetwork.bfu (http://\"http://webpages.charter.net/cretemonster/p2pnetwork.bfu\")
Now click the execute button and let the script run!
Reboot into SAFE MODE(F5 or F8 when restarting)
Here is a link on how to boot into Safe Mode:
SafeMode (http://\"http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406?OpenDocument&src=sec_doc_nam\")
Once in Safe Mode-> From the WinPFind folder-> Doubleclick WinPFind.exe and Click "Start Scan"
It will scan the entire System, so please be patient!
One you see "Scan Complete"-> a log (WinPFind.txt) will be automatically generated in the WinPFind folder!
Run MSCONFIG and enable everything in the startup area. To get to MSCONFIG, click on Start -> Run -> Type in MSCONFIG -> click OK.
Under the "General" Tab
Make Sure Normal Startup is Checked!!
Select the tab labeled Startup and put a Check by every box there!! Once everything is enabled, run "Hijack This!" and post a new log to this thread!!
Restart Normal and have the PC Scanned here:
Panda Active Scan (http://\"http://www.pandasoftware.com/products/activescan/com/activescan_principal.htm\")
You will need to be using Internet Explorer for the Scan to work!
Save the Report it generates!
Post back with a fresh HijackThis log and the reports from WinPFind and Panda!
-
This has helped me so much! I followed your directions and now my computer is fine! Thank you!!!
/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />
-
Hello I have followed the directions above and these are my results:
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 4:31:01 AM, on 10/18/2005
Platform: Windows XP SP2, v.2055 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2055)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hijackthis!\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01 (http://\"http://g.msn.com/0SEENUS/SAOS01\")
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.nl/ (http://\"http://www.google.nl/\")
R3 - URLSearchHook: (no name) - {D8F1D472-D201-2297-8BD5-72CC290E4A82} - EXE32EXE.dll (file missing)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [UserSp1] startman.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\PRISMSVR.EXE" /APPLY
O4 - HKCU\..\Run: [Dest068] SYSTRAV.exe
O4 - HKCU\..\Run: [CToolBar] StartCpl.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: SpeedTouch 121g Wireless USB Monitor.lnk = C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\st121g.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab\")
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 (http://\"http://go.microsoft.com/fwlink/?linkid=39204\")
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab (http://\"http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab\")
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab (http://\"http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab\")
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B5FE67A-15BF-4A47-A256-65CBD1BB074E}: NameServer = 69.50.176.158,85.255.112.8
O17 - HKLM\System\CCS\Services\Tcpip\..\{E27FB89E-8A71-492A-ABFB-A44132D0A21B}: NameServer = 69.50.176.158,85.255.112.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{5B5FE67A-15BF-4A47-A256-65CBD1BB074E}: NameServer = 69.50.176.158,85.255.112.8
O17 - HKLM\System\CS2\Services\Tcpip\..\{5B5FE67A-15BF-4A47-A256-65CBD1BB074E}: NameServer = 69.50.176.158,85.255.112.8
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
WinPFind log:
»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP Current Build: Service Pack 2, v.2055 Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2055
»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»
Checking %SystemDrive% folder...
Checking %ProgramFilesDir% folder...
Checking %WinDir% folder...
UPX! 8/18/2005 1:53:08 AM 14336 C:\WINDOWS\q16333078_disk.dll
Checking %System% folder...
PEC2 8/23/2001 8:00:00 PM 41397 C:\WINDOWS\SYSTEM32\dfrg.msc
winsync 8/23/2001 8:00:00 PM 1309184 C:\WINDOWS\SYSTEM32\wbdbase.deu
Umonitor 12/16/2003 8:25:14 PM 640000 C:\WINDOWS\SYSTEM32\rasdlg.dll
PTech 7/12/2005 5:50:44 PM 520456 C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
FSG! 8/18/2005 1:53:00 AM 705 C:\WINDOWS\SYSTEM32\msexnpbi.exe
UPX! 11/2/2004 6:28:08 AM 224768 C:\WINDOWS\SYSTEM32\b4fm.dll
Checking %System%\Drivers folder and sub-folders...
Items found in C:\WINDOWS\SYSTEM32\drivers\etc\hosts
Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
10/18/2005 3:59:56 AM S 2048 C:\WINDOWS\bootstat.dat
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\netstat.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\ping.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\tracert.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\tasklist.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\taskkill.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\regedit.com
10/18/2005 3:46:32 AM HS 2 C:\WINDOWS\system32\cmd.com
10/18/2005 3:59:10 AM H 749568 C:\WINDOWS\system32\config\system.LOG
10/18/2005 3:59:10 AM H 90112 C:\WINDOWS\system32\config\software.LOG
10/18/2005 3:59:10 AM H 8192 C:\WINDOWS\system32\config\default.LOG
10/18/2005 4:00:12 AM H 1024 C:\WINDOWS\system32\config\SAM.LOG
10/18/2005 3:59:56 AM H 12288 C:\WINDOWS\system32\config\SECURITY.LOG
9/22/2005 3:45:30 AM HS 24 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\Preferred
9/22/2005 3:45:30 AM HS 388 C:\WINDOWS\system32\Microsoft\Protect\S-1-5-18\User\f0307e1e-9beb-4d91-a7e0-ba40fa66f62d
10/18/2005 3:59:06 AM H 6 C:\WINDOWS\Tasks\SA.DAT
10/18/2005 3:59:04 AM S 64 C:\WINDOWS\CSC\00000001
9/21/2005 11:00:38 PM S 64 C:\WINDOWS\CSC\csc1.tmp
10/8/2005 6:03:56 AM S 64 C:\WINDOWS\CSC\00000002
Checking for CPL files...
Microsoft Corporation 8/23/2001 8:00:00 PM 187904 C:\WINDOWS\SYSTEM32\main.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 559616 C:\WINDOWS\SYSTEM32\mmsys.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 35840 C:\WINDOWS\SYSTEM32\ncpa.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 36864 C:\WINDOWS\SYSTEM32\nwc.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 109056 C:\WINDOWS\SYSTEM32\powercfg.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 28160 C:\WINDOWS\SYSTEM32\telephon.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 90112 C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 132096 C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 534528 C:\WINDOWS\SYSTEM32\appwiz.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 29696 C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 153088 C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 313856 C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 124928 C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation 12/16/2003 8:31:02 PM 441344 C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 67072 C:\WINDOWS\SYSTEM32\joy.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 257024 C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 32768 C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 281088 C:\WINDOWS\SYSTEM32\sysdm.cpl
Sun Microsystems, Inc. 3/4/2005 3:36:44 AM 49265 C:\WINDOWS\SYSTEM32\jpicpl32.cpl
5/25/2004 7:06:58 AM 417792 C:\WINDOWS\SYSTEM32\ac3filter.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 534528 C:\WINDOWS\SYSTEM32\dllcache\appwiz.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 36864 C:\WINDOWS\SYSTEM32\dllcache\nwc.cpl
Microsoft Corporation 12/16/2003 1:25:22 PM 132096 C:\WINDOWS\SYSTEM32\dllcache\desk.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 29696 C:\WINDOWS\SYSTEM32\dllcache\firewall.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 153088 C:\WINDOWS\SYSTEM32\dllcache\hdwwiz.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 32768 C:\WINDOWS\SYSTEM32\dllcache\odbccp32.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 313856 C:\WINDOWS\SYSTEM32\dllcache\inetcpl.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 124928 C:\WINDOWS\SYSTEM32\dllcache\intl.cpl
Microsoft Corporation 8/23/2001 1:00:00 PM 66048 C:\WINDOWS\SYSTEM32\dllcache\access.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 67072 C:\WINDOWS\SYSTEM32\dllcache\joy.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 35840 C:\WINDOWS\SYSTEM32\dllcache\ncpa.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 257024 C:\WINDOWS\SYSTEM32\dllcache\nusrmgr.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 109056 C:\WINDOWS\SYSTEM32\dllcache\powercfg.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 187904 C:\WINDOWS\SYSTEM32\dllcache\main.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 559616 C:\WINDOWS\SYSTEM32\dllcache\mmsys.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 151552 C:\WINDOWS\SYSTEM32\dllcache\sapi.cpl
Microsoft Corporation 12/16/2003 8:25:22 PM 281088 C:\WINDOWS\SYSTEM32\dllcache\sysdm.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 28160 C:\WINDOWS\SYSTEM32\dllcache\telephon.cpl
Microsoft Corporation 8/23/2001 8:00:00 PM 90112 C:\WINDOWS\SYSTEM32\dllcache\timedate.cpl
Microsoft Corporation 12/16/2003 1:25:22 PM 52224 C:\WINDOWS\SYSTEM32\dllcache\wuaucpl.cpl
»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»
Checking files in %ALLUSERSPROFILE%\Startup folder...
6/19/2005 5:10:36 AM HS 84 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
6/19/2005 5:22:34 AM 1694 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
10/6/2005 3:33:56 AM 1641 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
9/27/2005 11:10:42 AM 970 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\SpeedTouch 121g Wireless USB Monitor.lnk
6/20/2005 3:36:22 PM 1429 C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WinZip Quick Pick.lnk
Checking files in %ALLUSERSPROFILE%\Application Data folder...
6/19/2005 5:03:04 AM HS 62 C:\Documents and Settings\All Users\Application Data\desktop.ini
Checking files in %USERPROFILE%\Startup folder...
6/19/2005 5:10:36 AM HS 84 C:\Documents and Settings\XANDER\Start Menu\Programs\Startup\desktop.ini
Checking files in %USERPROFILE%\Application Data folder...
6/19/2005 5:03:04 AM HS 62 C:\Documents and Settings\XANDER\Application Data\desktop.ini
12/23/2004 4:43:14 AM 4713 C:\Documents and Settings\XANDER\Application Data\wo.tmp
»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
{09799AFB-AD67-11d1-ABCD-00C04FC30936} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
Start Menu Pin = %SystemRoot%\system32\SHELL32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
{A470F8CF-A1E8-4f65-8335-227475AA5C46} = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
{750fdf0e-2a26-11d1-a3ea-080036587f03} = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6} = ntshrui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\WinZip
{E0D79304-84BE-11CE-9641-444553540000} = C:\PROGRA~1\WINZIP\WZSHLSTB.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
= %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
= %SystemRoot%\system32\SHELL32.dll
[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
AcroIEHlprObj Class = C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}
= C:\PROGRA~1\SPYBOT~1\SDHelper.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9394EDE7-C8B5-483E-8773-474BF36AF6E4}
ST = C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}
MSNToolBandBHO = C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
&Tip of the Day = %SystemRoot%\System32\shdocvw.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
{8E718888-423F-11D2-876E-00A0C9082467} = &Radio : C:\WINDOWS\System32\msdxm.ocx
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
MenuText = Sun Java Console : C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{2D663D1A-8670-49D9-A1A5-4C56B4E14E84}
MenuText = :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{6224f700-cba3-4071-b251-47cb894244cd}
ButtonText = ICQ Pro : C:\PROGRA~1\ICQ\ICQ.exe
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{32683183-48a0-441b-a342-7c2a440a9478}
Media Band = %SystemRoot%\System32\browseui.dll
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars\{C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
File Search Explorer Band = %SystemRoot%\system32\SHELL32.dll
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{08BEC6AA-49FC-4379-3587-4B21E286C19E} = :
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
{01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address : %SystemRoot%\System32\browseui.dll
{0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links : %SystemRoot%\system32\SHELL32.dll
{BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} = MSN : C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
{70DE7956-479D-4EB7-8641-2B45774C350E} = :
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
BluetoothAuthenticationAgent rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
SunJavaUpdateSched C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
WinampAgent C:\Program Files\Winamp\winampa.exe
AudioDeck C:\Program Files\VIAudioi\SBADeck\ADeck.exe 1
Mirabilis ICQ C:\PROGRA~1\ICQ\ICQNet.exe
iTunesHelper "C:\Program Files\iTunes\iTunesHelper.exe"
winupdates C:\Program Files\winupdates\winupdates.exe /auto
UserSp1 startman.exe
NeroFilterCheck C:\WINDOWS\system32\NeroCheck.exe
PRISMSVR.EXE "C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\PRISMSVR.EXE" /APPLY
PRISMSVR.EXE "C:\Program Files\Thomson SpeedTouch\SpeedTouch 121g Wireless USB Monitor\PRISMSVR.EXE" /APPLY
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
IMAIL Installed = 1
MAPI Installed = 1
MSFS Installed = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Dest068 SYSTRAV.exe
CToolBar StartCpl.exe
ctfmon.exe C:\WINDOWS\System32\ctfmon.exe
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
{BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
{0DF44EAA-FF21-4412-828E-260A8728E7F1} =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
dontdisplaylastusername 0
legalnoticecaption
legalnoticetext
shutdownwithoutlogon 1
undockwithoutlogon 1
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun 145
NoBandCustomize 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
PostBootReminder {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
CDBurn {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
WebCheck {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
SysTray {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Shell = Explorer.exe
System =
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
= crypt32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
= cryptnet.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
= cscdll.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
= wlnotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
= sclgntfy.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
= WlNotify.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
= wlnotify.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
Debugger = ntsd -d
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs
»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.4.1 - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 10/18/2005 4:05:30 AM
Panda log:
Incident Status Location
Virus:Trj/Downloader.EEV Disinfected C:\WINDOWS\q16333078_disk.dll
Adware:adware/sbsoft No disinfected C:\WINDOWS\rdt.ini
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\XANDER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-29893042-422de001.zip[GetAccess.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\XANDER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-29893042-422de001.zip[InsecureClassLoader.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\XANDER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-29893042-422de001.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\XANDER\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\classload.jar-29893042-422de001.zip[Installer.class]
Spyware:spyware/wareout No disinfected C:\Documents and Settings\XANDER\Application Data\wo.tmp
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Trojan Remover 6.3.5.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\FileRecoveryAngel 1.06.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\ImTOO Mpeg Encoder 2.1.55.1008b.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Default Printer 2.1.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Hitman 2.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Moto GP 3.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\File Utilities.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Maxthon.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\TVolution 1.0.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Mcft Windows XP Scene Edition 1.6 INTER.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\DVD to AVI DivX MPEG Ripper converts 7gb.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Visual.CertExam.Suite 1.7.542.CHiCNCREA.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Boris RED 3GL incl Plugins.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\PHPMaker 3.02.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\HiDownload 6.4.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Download Tunnel Me 2.0.1 , set up tunne.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Simpsons hit and run.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Batman Begins.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\HTMLRunExe 2.0.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Clipboard Box 2.2.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\MaxBulk Mailer 4.3.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\QuickTime Alternative 1.63.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Real Alternative 1.44.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\ArtMoney 7.14.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\I-Sound WMA MP3 Recorder Pro 6.57.3.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Cute CD DVD Burner 2.3.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\C-Organizer Professional 3.4.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\PowerGREP 3.2.0.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Foxy 1.0.4.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\UltraISO 7.65.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Reportizer 2.2.5.73.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Screen VidShot 2.1.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Macro Recorder 2.11.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\EditPlus V. 2.20.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\SMS Create Pro 5.5.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Panda Titanium Antivirus.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\CorelDRAW Graphics Suite 12.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\Ulead PhotoImpact 11.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\DZSoft PHP Editor 3.5.0.2.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Documents and Settings\XANDER\Complete\SQL Server Backup 4.01.zip[Setup.exe]
Virus:W32/Alcan.A.worm Disinfected C:\Program Files\winupdates\winupdates.exe
Virus:W32/Alcan.A.worm Disinfected C:\Program Files\winupdates\a.tmp
Virus:W32/Alcan.A.worm Disinfected C:\Program Files\winupdates\a.zip[Setup.exe]
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0009708.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0009716.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0010708.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0010721.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011708.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011720.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011746.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011759.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011762.EXE
Adware:Adware/Findspy No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011763.exe
Adware:Adware/QuickWeb No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011764.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011772.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011785.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011788.EXE
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011794.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011807.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011818.EXE
Adware:Adware/Findspy No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011819.exe
Adware:Adware/QuickWeb No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0011823.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0012795.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0012820.exe
Spyware:Spyware/WareOut No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0012835.exe
Spyware:Spyware/WareOut No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0012836.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0013795.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP40\A0013812.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0013871.exe
Adware:Adware/Findspy No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0013872.exe
Adware:Adware/QuickWeb No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0013873.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0014795.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0014801.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015795.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015810.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015853.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015864.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015865.EXE
Adware:Adware/Findspy No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015866.exe
Adware:Adware/QuickWeb No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP41\A0015867.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015878.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015889.exe
Virus:Trj/Qhost.BP Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015891.exe
Adware:Adware/Findspy No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015892.EXE
Adware:Adware/QuickWeb No disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015893.EXE
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015900.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015911.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015913.exe
Virus:Trj/Troiram.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-40CE-9E49-56E1BAFAA524}\RP42\A0015924.exe
Virus:Trj/DelCache.A Disinfected C:\System Volume Information\_restore{58931BB6-457C-
-
Locking this topic as the original poster has not returned
All others Please, Read this (http://\"http://www.thetechguide.com/forum/index.php?showtopic=14623\")