1
Tech Clinic / HJT Log Help
« on: November 28, 2007, 06:13:39 PM »
37521.exe;c:\documents and settings\suzanne dement\application data;Trojan.DownLoader.36835;Deleted.;
aolconnfix.exe;C:\;Trojan.PWS.Gamania.origin;Incurable.Moved.;
49181.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.DownLoader.36835;Deleted.;
pcpriv.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.DownLoader.36408;Deleted.;
printer.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.Fakealert.378;Deleted.;
GTDownDE_87.ocx;C:\i386;Adware.Gdown;Moved.;
autorun.exe.vir;C:\qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Startup;Trojan.Fakealert.378;Deleted.;
findfast.exe.vir;C:\qoobox\Quarantine\C\Documents and Settings\Suzanne Dement\Start Menu\Programs\Startup;Trojan.Fakealert.378;Deleted.;
3269.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.DownLoader.based;Deleted.;
func.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Click.1237;Deleted.;
spoolsv.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Click.origin;Incurable.Moved.;
xloader10181.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Fakealert;Deleted.;
lawu.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
lawu832.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
lawu862.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
Yazzle1162OinAdmin.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Adware.ClickSpring;Moved.;
Yazzle1549OinAdmin.exe.vir\data001;C:\qoobox\Quarantine\C\Program Files\Common Files\Yazzle1549OinAdmin.exe.vir;Adware.MediaTicket.origin;;
Yazzle1549OinAdmin.exe.vir\data002;C:\qoobox\Quarantine\C\Program Files\Common Files\Yazzle1549OinAdmin.exe.vir;Trojan.PurityAd.origin;;
Yazzle1549OinAdmin.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Archive contains infected objects;Moved.;
chkdsk.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files\MCROSO~1.NET;Trojan.DownLoader.22753;Deleted.;
holesudu4444.dll.vir;C:\qoobox\Quarantine\C\Program Files\Windows NT;Adware.Ttc;Moved.;
holesudu83122.dll.vir;C:\qoobox\Quarantine\C\Program Files\Windows NT;Adware.Ttc;Moved.;
jctzxafg.dll.bad.vir;C:\qoobox\Quarantine\C\VundoFix Backups;Trojan.Fakealert.372;Deleted.;
npkmscxj.dll.bad.vir;C:\qoobox\Quarantine\C\VundoFix Backups;Trojan.Fakealert.372;Deleted.;
avp.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.25873;Deleted.;
mgrs.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.25873;Deleted.;
mrofinu1000106.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.31817;Deleted.;
mrofinu77.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.31817;Deleted.;
shell.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.Fakealert.378;Deleted.;
agrhoxkj.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.232;Deleted.;
bjhtsokx.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
fcccawv.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.230;Deleted.;
ibncxiq.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Adware.ClickSpring.origin;Moved.;
ldcore.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.DownLoader.37335;Deleted.;
printer.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.378;Deleted.;
qyfufaql.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.25;Deleted.;
rlprtgtx.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
spoolvs.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.378;Deleted.;
vpbwnuce.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
winkvs32.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Mezzia;Deleted.;
ybdhdmdg.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.25;Deleted.;
dnslook11.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32\b1;Trojan.DownLoader.5013;Deleted.;
asappsrv.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\U3V6YW5uZSBEZW1lbnQ;Trojan.Proxy.493;Deleted.;
A0036553.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Adware.Ttc;Moved.;
A0036554.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.DownLoader.24715;Deleted.;
A0036555.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.Proxy.493;Deleted.;
A0036556.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.PurityAd.origin;Incurable.Moved.;
A0036561.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.DownLoader.31817;Deleted.;
A0036566.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.Fakealert;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393\snapshot;Adware.Ttc;Moved.;
A0036806.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.Click.4740;Deleted.;
A0036811.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Adware.MyWay;Moved.;
A0037851.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.based;Deleted.;
A0037853.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Adware.Ttc;Moved.;
A0037857.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DnsChange;Deleted.;
A0037864.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.22753;Deleted.;
A0038874.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.25873;Deleted.;
A0038875.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038876.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038878.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038879.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038908.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038909.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038910.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038911.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0039885.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039886.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039894.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Adware.ClickSpring;Moved.;
A0039896.exe\data001;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0039896.exe;Adware.MediaTicket.origin;;
A0039896.exe\data002;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0039896.exe;Trojan.PurityAd.origin;;
A0039896.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Archive contains infected objects;Moved.;
A0039901.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.31817;Deleted.;
A0039902.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.31817;Deleted.;
A0039903.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039904.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039905.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039910.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Adware.ClickSpring.origin;Moved.;
A0039911.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039912.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039913.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039914.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Mezzia;Deleted.;
A0039915.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Virtumod.232;Deleted.;
A0039916.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Juan.25;Deleted.;
A0039918.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Juan.25;Deleted.;
A0039920.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Proxy.493;Deleted.;
A0039921.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.22753;Deleted.;
A0039923.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.5013;Deleted.;
A0039931.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.37335;Deleted.;
A0039932.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039933.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.25873;Deleted.;
A0039937.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.25873;Deleted.;
A0039939.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039940.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039942.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.based;Deleted.;
A0039943.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert;Deleted.;
A0040176.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Click.1237;Deleted.;
A0040177.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Click.origin;Incurable.Moved.;
A0040178.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Adware.Ttc;Moved.;
A0040179.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Adware.Ttc;Moved.;
A0040183.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Virtumod.230;Deleted.;
A0040342.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.DownLoader.36835;Deleted.;
A0040344.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.PWS.Gamania.origin;Incurable.Moved.;
A0040345.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.DownLoader.36408;Deleted.;
A0040346.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.Fakealert.378;Deleted.;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:22 PM, on 11/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\ESDUSBMon.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Venturi2\Configurator\ventcfg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Venturi Configurator] C:\Program Files\Venturi2\Configurator\ventcfg.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ESDUSBMon.exe] C:\WINDOWS\system32\ESDUSBMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\append.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 6207 bytes
ComboFix 07-11-28.2 - Suzanne Dement 2007-11-28 15:48:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.667 [GMT -6:00]
Running from: C:\Documents and Settings\Suzanne Dement\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Suzanne Dement\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Suzanne Dement\mit.bat
C:\Program Files\Del.js
C:\Program Files\func.exe
C:\Program Files\func.js
C:\Program Files\spoolsv.exe
C:\Program Files\Windows NT\holesudu4444.dll
C:\Program Files\Windows NT\holesudu83122.dll
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
C:\WINDOWS\system32\drvnib.dll
C:\WINDOWS\system32\fcccawv.dll
C:\WINDOWS\system32\mvisdfcb.ini
C:\WINDOWS\system32\pmnnnkl.dll
C:\WINDOWS\system32\sgecreva.ini
C:\WINDOWS\system32\vtsqomk.dll
C:\WINDOWS\system32\VundoFixSVC.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Suzanne Dement\mit.bat
C:\Program Files\Del.js
C:\Program Files\E404 Helper
C:\Program Files\E404 Helper\e404.v6.dll
C:\Program Files\func.exe
C:\Program Files\func.js
C:\Program Files\spoolsv.exe
C:\Program Files\Windows NT\holesudu4444.dll
C:\Program Files\Windows NT\holesudu83122.dll
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\VundoFix Backups
C:\VundoFix Backups\drvnibr.dll.bad
C:\VundoFix Backups\ihhkj.ini.bad
C:\VundoFix Backups\ihhkj.ini2.bad
C:\VundoFix Backups\jctzxafg.dll.bad
C:\VundoFix Backups\jctzxafg.dllbox.bad
C:\VundoFix Backups\jkhhi.dll.bad
C:\VundoFix Backups\npkmscxj.dll.bad
C:\VundoFix Backups\vtsqomk.dll.bad
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\cc1
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
C:\WINDOWS\system32\drvnib.dll
C:\WINDOWS\system32\fcccawv.dll
C:\WINDOWS\system32\mvisdfcb.ini
C:\WINDOWS\system32\pmnnnkl.dll
C:\WINDOWS\system32\sgecreva.ini
C:\WINDOWS\system32\vtsqomk.dll
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\U3V6YW5uZSBEZW1lbnQ
C:\WINDOWS\U3V6YW5uZSBEZW1lbnQ\oapdsqcRtm1HtqY5vBk.vbs
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-28 )))))))))))))))))))))))))))))))
.
2007-11-28 15:32 . 2007-11-28 15:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-27 21:30 . 2005-04-03 23:03 204,832 --a------ C:\Documents and Settings\Suzanne Dement\Application Data\pcpriv.exe
2007-11-27 21:18 . 2007-11-27 21:18 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-27 14:44 . 2007-11-28 15:51 18,432 --a------ C:\WINDOWS\system32\append.dll
2007-11-23 19:42 . 2007-11-23 19:42 <DIR> d-------- C:\Documents and Settings\Suzanne Dement\Application Data\ultra
2007-11-21 18:07 . 2005-03-20 23:54 9,728 --a------ C:\Documents and Settings\Suzanne Dement\Application Data\printer.exe
2007-11-21 17:48 . 2005-05-10 12:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-11-21 17:48 . 2005-05-10 12:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-11-21 17:48 . 2005-05-10 11:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2007-11-21 17:48 . 2007-02-06 12:01 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2007-11-20 20:44 . 2007-11-20 20:45 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-11-20 20:23 . 2007-11-20 20:23 1,147,424 --a------ C:\Install
2007-11-20 20:20 . 2007-11-28 15:49 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 21:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 02:51 --------- d-----w C:\Documents and Settings\Suzanne Dement\Application Data\Lavasoft
2007-11-21 02:17 --------- d-----w C:\Documents and Settings\Suzanne Dement\Application Data\Apple Computer
2006-09-28 00:00 563,712 ----a-w C:\Documents and Settings\Suzanne Dement\gotomypc_370.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Temp ----
2007-11-20 20:20 1858 --a------ C:\Temp\abW9\tPho.log
((((((((((((((((((((((((((((( snapshot@2007-11-28_11.08.51.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-28 21:32:39 632,320 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}\IconCD95F66110.exe
+ 2007-11-28 21:32:39 29,184 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}\IconCD95F6617.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 15:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 13:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 20:00]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 15:54]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-05-10 12:04]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41]
"Venturi Configurator"="C:\Program Files\Venturi2\Configurator\ventcfg.exe" [2004-03-08 13:48]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 12:38]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18]
"ESDUSBMon.exe"="C:\WINDOWS\system32\ESDUSBMon.exe" [2005-05-26 20:11]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\append.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, append.dll
S3 nwusbmdm;Novatel Wireless Merlin CDMA EV-DO Modem Driver;C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys
S3 nwusbser;Novatel Wireless Merlin CDMA EV-DO Status Port;C:\WINDOWS\system32\DRIVERS\nwusbser.sys
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;\??\C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:40:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-28 15:51:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-28 15:53:14 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-28 11:09
.
--- E O F ---
aolconnfix.exe;C:\;Trojan.PWS.Gamania.origin;Incurable.Moved.;
49181.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.DownLoader.36835;Deleted.;
pcpriv.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.DownLoader.36408;Deleted.;
printer.exe;C:\Documents and Settings\Suzanne Dement\Application Data;Trojan.Fakealert.378;Deleted.;
GTDownDE_87.ocx;C:\i386;Adware.Gdown;Moved.;
autorun.exe.vir;C:\qoobox\Quarantine\C\Documents and Settings\All Users\Start Menu\Programs\Startup;Trojan.Fakealert.378;Deleted.;
findfast.exe.vir;C:\qoobox\Quarantine\C\Documents and Settings\Suzanne Dement\Start Menu\Programs\Startup;Trojan.Fakealert.378;Deleted.;
3269.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.DownLoader.based;Deleted.;
func.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Click.1237;Deleted.;
spoolsv.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Click.origin;Incurable.Moved.;
xloader10181.exe.vir;C:\qoobox\Quarantine\C\Program Files;Trojan.Fakealert;Deleted.;
lawu.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
lawu832.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
lawu862.dll.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Trojan.StartPage.19992;Deleted.;
Yazzle1162OinAdmin.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Adware.ClickSpring;Moved.;
Yazzle1549OinAdmin.exe.vir\data001;C:\qoobox\Quarantine\C\Program Files\Common Files\Yazzle1549OinAdmin.exe.vir;Adware.MediaTicket.origin;;
Yazzle1549OinAdmin.exe.vir\data002;C:\qoobox\Quarantine\C\Program Files\Common Files\Yazzle1549OinAdmin.exe.vir;Trojan.PurityAd.origin;;
Yazzle1549OinAdmin.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files;Archive contains infected objects;Moved.;
chkdsk.exe.vir;C:\qoobox\Quarantine\C\Program Files\Common Files\MCROSO~1.NET;Trojan.DownLoader.22753;Deleted.;
holesudu4444.dll.vir;C:\qoobox\Quarantine\C\Program Files\Windows NT;Adware.Ttc;Moved.;
holesudu83122.dll.vir;C:\qoobox\Quarantine\C\Program Files\Windows NT;Adware.Ttc;Moved.;
jctzxafg.dll.bad.vir;C:\qoobox\Quarantine\C\VundoFix Backups;Trojan.Fakealert.372;Deleted.;
npkmscxj.dll.bad.vir;C:\qoobox\Quarantine\C\VundoFix Backups;Trojan.Fakealert.372;Deleted.;
avp.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.25873;Deleted.;
mgrs.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.25873;Deleted.;
mrofinu1000106.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.31817;Deleted.;
mrofinu77.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.DownLoader.31817;Deleted.;
shell.exe.vir;C:\qoobox\Quarantine\C\WINDOWS;Trojan.Fakealert.378;Deleted.;
agrhoxkj.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.232;Deleted.;
bjhtsokx.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
fcccawv.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.230;Deleted.;
ibncxiq.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Adware.ClickSpring.origin;Moved.;
ldcore.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.DownLoader.37335;Deleted.;
printer.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.378;Deleted.;
qyfufaql.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.25;Deleted.;
rlprtgtx.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
spoolvs.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Fakealert.378;Deleted.;
vpbwnuce.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.EzulaAd;Deleted.;
winkvs32.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Mezzia;Deleted.;
ybdhdmdg.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.25;Deleted.;
dnslook11.exe.vir;C:\qoobox\Quarantine\C\WINDOWS\system32\b1;Trojan.DownLoader.5013;Deleted.;
asappsrv.dll.vir;C:\qoobox\Quarantine\C\WINDOWS\U3V6YW5uZSBEZW1lbnQ;Trojan.Proxy.493;Deleted.;
A0036553.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Adware.Ttc;Moved.;
A0036554.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.DownLoader.24715;Deleted.;
A0036555.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.Proxy.493;Deleted.;
A0036556.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.PurityAd.origin;Incurable.Moved.;
A0036561.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.DownLoader.31817;Deleted.;
A0036566.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393;Trojan.Fakealert;Deleted.;
MFEX-1.DAT;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP393\snapshot;Adware.Ttc;Moved.;
A0036806.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.Click.4740;Deleted.;
A0036811.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Adware.MyWay;Moved.;
A0037851.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.based;Deleted.;
A0037853.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Adware.Ttc;Moved.;
A0037857.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DnsChange;Deleted.;
A0037864.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.22753;Deleted.;
A0038874.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP398;Trojan.DownLoader.25873;Deleted.;
A0038875.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038876.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038878.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038879.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP399;Trojan.Fakealert.378;Deleted.;
A0038908.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038909.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038910.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0038911.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP400;Trojan.Fakealert.378;Deleted.;
A0039885.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039886.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039894.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Adware.ClickSpring;Moved.;
A0039896.exe\data001;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0039896.exe;Adware.MediaTicket.origin;;
A0039896.exe\data002;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401\A0039896.exe;Trojan.PurityAd.origin;;
A0039896.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Archive contains infected objects;Moved.;
A0039901.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.31817;Deleted.;
A0039902.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.31817;Deleted.;
A0039903.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039904.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039905.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.EzulaAd;Deleted.;
A0039910.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Adware.ClickSpring.origin;Moved.;
A0039911.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039912.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039913.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.StartPage.19992;Deleted.;
A0039914.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Mezzia;Deleted.;
A0039915.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Virtumod.232;Deleted.;
A0039916.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Juan.25;Deleted.;
A0039918.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Juan.25;Deleted.;
A0039920.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Proxy.493;Deleted.;
A0039921.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.22753;Deleted.;
A0039923.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.5013;Deleted.;
A0039931.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.37335;Deleted.;
A0039932.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039933.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.25873;Deleted.;
A0039937.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.25873;Deleted.;
A0039939.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039940.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert.378;Deleted.;
A0039942.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.DownLoader.based;Deleted.;
A0039943.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP401;Trojan.Fakealert;Deleted.;
A0040176.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Click.1237;Deleted.;
A0040177.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Click.origin;Incurable.Moved.;
A0040178.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Adware.Ttc;Moved.;
A0040179.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Adware.Ttc;Moved.;
A0040183.dll;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP404;Trojan.Virtumod.230;Deleted.;
A0040342.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.DownLoader.36835;Deleted.;
A0040344.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.PWS.Gamania.origin;Incurable.Moved.;
A0040345.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.DownLoader.36408;Deleted.;
A0040346.exe;C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP406;Trojan.Fakealert.378;Deleted.;
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:22 PM, on 11/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\ESDUSBMon.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Venturi2\Configurator\ventcfg.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\EpStsSrv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Venturi2\Client\ventc.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Venturi Configurator] C:\Program Files\Venturi2\Configurator\ventcfg.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ESDUSBMon.exe] C:\WINDOWS\system32\ESDUSBMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {106E49CF-797A-11D2-81A2-00E02C015623} (AlternaTIFF ActiveX) - http://www.alternatiff.com/install/00/alttiff.cab
O20 - AppInit_DLLs: C:\WINDOWS\system32\append.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EPSON ESC/POS Status Service (EPSON ESCPOS Status Service) - SEIKO EPSON Corp. - C:\WINDOWS\SYSTEM32\EpStsSrv.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Venturi2 Client (Venturi2) - Venturi Wireless - C:\Program Files\Venturi2\Client\ventc.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 6207 bytes
ComboFix 07-11-28.2 - Suzanne Dement 2007-11-28 15:48:13.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.667 [GMT -6:00]
Running from: C:\Documents and Settings\Suzanne Dement\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Suzanne Dement\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Suzanne Dement\mit.bat
C:\Program Files\Del.js
C:\Program Files\func.exe
C:\Program Files\func.js
C:\Program Files\spoolsv.exe
C:\Program Files\Windows NT\holesudu4444.dll
C:\Program Files\Windows NT\holesudu83122.dll
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
C:\WINDOWS\system32\drvnib.dll
C:\WINDOWS\system32\fcccawv.dll
C:\WINDOWS\system32\mvisdfcb.ini
C:\WINDOWS\system32\pmnnnkl.dll
C:\WINDOWS\system32\sgecreva.ini
C:\WINDOWS\system32\vtsqomk.dll
C:\WINDOWS\system32\VundoFixSVC.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Suzanne Dement\mit.bat
C:\Program Files\Del.js
C:\Program Files\E404 Helper
C:\Program Files\E404 Helper\e404.v6.dll
C:\Program Files\func.exe
C:\Program Files\func.js
C:\Program Files\spoolsv.exe
C:\Program Files\Windows NT\holesudu4444.dll
C:\Program Files\Windows NT\holesudu83122.dll
C:\Temp\abW9
C:\Temp\abW9\tPho.log
C:\VundoFix Backups
C:\VundoFix Backups\drvnibr.dll.bad
C:\VundoFix Backups\ihhkj.ini.bad
C:\VundoFix Backups\ihhkj.ini2.bad
C:\VundoFix Backups\jctzxafg.dll.bad
C:\VundoFix Backups\jctzxafg.dllbox.bad
C:\VundoFix Backups\jkhhi.dll.bad
C:\VundoFix Backups\npkmscxj.dll.bad
C:\VundoFix Backups\vtsqomk.dll.bad
C:\WINDOWS\system32\append.dll
C:\WINDOWS\system32\cc1
C:\WINDOWS\system32\ClickToFindandFixErrors_US.ico
C:\WINDOWS\system32\drvnib.dll
C:\WINDOWS\system32\fcccawv.dll
C:\WINDOWS\system32\mvisdfcb.ini
C:\WINDOWS\system32\pmnnnkl.dll
C:\WINDOWS\system32\sgecreva.ini
C:\WINDOWS\system32\vtsqomk.dll
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\U3V6YW5uZSBEZW1lbnQ
C:\WINDOWS\U3V6YW5uZSBEZW1lbnQ\oapdsqcRtm1HtqY5vBk.vbs
.
((((((((((((((((((((((((( Files Created from 2007-10-28 to 2007-11-28 )))))))))))))))))))))))))))))))
.
2007-11-28 15:32 . 2007-11-28 15:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WinZip
2007-11-27 21:30 . 2005-04-03 23:03 204,832 --a------ C:\Documents and Settings\Suzanne Dement\Application Data\pcpriv.exe
2007-11-27 21:18 . 2007-11-27 21:18 <DIR> d-------- C:\Program Files\Trend Micro
2007-11-27 14:44 . 2007-11-28 15:51 18,432 --a------ C:\WINDOWS\system32\append.dll
2007-11-23 19:42 . 2007-11-23 19:42 <DIR> d-------- C:\Documents and Settings\Suzanne Dement\Application Data\ultra
2007-11-21 18:07 . 2005-03-20 23:54 9,728 --a------ C:\Documents and Settings\Suzanne Dement\Application Data\printer.exe
2007-11-21 17:48 . 2005-05-10 12:10 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Sonic
2007-11-21 17:48 . 2005-05-10 12:00 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Jasc Software Inc
2007-11-21 17:48 . 2005-05-10 11:45 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intel
2007-11-21 17:48 . 2007-02-06 12:01 <DIR> d--h----- C:\Documents and Settings\Administrator\Application Data\Gtek
2007-11-20 20:44 . 2007-11-20 20:45 <DIR> d-------- C:\Program Files\Windows Live Safety Center
2007-11-20 20:23 . 2007-11-20 20:23 1,147,424 --a------ C:\Install
2007-11-20 20:20 . 2007-11-28 15:49 <DIR> d-------- C:\Temp
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-28 21:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-21 02:51 --------- d-----w C:\Documents and Settings\Suzanne Dement\Application Data\Lavasoft
2007-11-21 02:17 --------- d-----w C:\Documents and Settings\Suzanne Dement\Application Data\Apple Computer
2006-09-28 00:00 563,712 ----a-w C:\Documents and Settings\Suzanne Dement\gotomypc_370.exe
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\Temp ----
2007-11-20 20:20 1858 --a------ C:\Temp\abW9\tPho.log
((((((((((((((((((((((((((((( snapshot@2007-11-28_11.08.51.10 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-28 21:32:39 632,320 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}\IconCD95F66110.exe
+ 2007-11-28 21:32:39 29,184 ----a-r C:\WINDOWS\Installer\{CD95F661-A5C4-44F5-A6AA-ECDD91C240B5}\IconCD95F6617.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 04:00]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2004-09-13 15:33]
"IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2004-10-30 13:59]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-12-03 20:00]
"PCMService"="C:\Program Files\Dell\Media Experience\PCMService.exe" []
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 15:54]
"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-05-10 12:04]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 08:41]
"Venturi Configurator"="C:\Program Files\Venturi2\Configurator\ventcfg.exe" [2004-03-08 13:48]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 12:38]
"HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18]
"ESDUSBMon.exe"="C:\WINDOWS\system32\ESDUSBMon.exe" [2005-05-26 20:11]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll 2004-09-07 15:08 110592 C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\append.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, append.dll
S3 nwusbmdm;Novatel Wireless Merlin CDMA EV-DO Modem Driver;C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys
S3 nwusbser;Novatel Wireless Merlin CDMA EV-DO Status Port;C:\WINDOWS\system32\DRIVERS\nwusbser.sys
S3 SMNDIS5;SMNDIS5 NDIS Protocol Driver;\??\C:\PROGRA~1\VERIZO~1\VZACCE~1\SMNDIS5.SYS
.
Contents of the 'Scheduled Tasks' folder
"2007-09-14 18:40:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************
catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-28 15:51:52
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-28 15:53:14 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-28 11:09
.
--- E O F ---