Author Topic: malware aurora, trojans, etc  (Read 6555 times)

Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #20 on: August 30, 2005, 09:55:08 PM »
here are the logs

Logfile of HijackThis v1.99.1
Scan saved at 10:40:32 PM, on 8/30/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\ateiua.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [nvzsjwo] C:\WINDOWS\system32\ateiua.exe r
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




WindPfind




WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
abetterinternet.com  4/28/2002 9:07:34 AM        3506       C:\WINDOWS\abiuninst.htm
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 4/21/2005 4:28:22 PM        52736      C:\WINDOWS\Nail.exe
UPX!                 2/5/2003 11:10:06 AM        6656       C:\WINDOWS\svcproc.exe
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 2/24/2004 6:29:28 PM        28160      C:\WINDOWS\SYSTEM32\DrPMon.dll
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
UPX!                 2/20/2004 6:49:02 PM        77312      C:\WINDOWS\SYSTEM32\Ia1cm.dll
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     8/30/2005 10:39:00 PM     S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     8/30/2005 9:47:50 PM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     7/2/2005 4:18:16 AM       S 9445       C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB903235.cat
                     8/30/2005 10:40:06 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     8/30/2005 10:39:32 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     8/30/2005 10:40:06 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     8/30/2005 10:44:54 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     8/30/2005 10:44:54 PM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     8/30/2005 10:39:04 PM    H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
   nvzsjwo   C:\WINDOWS\system32\ateiua.exe r

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = Explorer.exe C:\WINDOWS\Nail.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/30/2005 10:45:35 PM

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #21 on: August 30, 2005, 11:10:41 PM »
Let's do some other steps, I wish we could get you into safe mode
But don't try it at this time

Please download the following
# Download DSRFIX from HERE onto your Desktop.

    * Unzip and EXTRACT the files to your Desktop.
    * The program creates and names the new folder to house the files.
    * DO NOT RUN IT YET

Please download the Nailfix utility.
DO NOT run it yet.

#  Please download Advanced Process Termination from:
http://www.diamondcs.com.au/downloads/apt.zip
Unzip it to the desktop.

Save these instructions or print this out
Close down all other windows including this one

Double-click on "My Computer" and navigate to C:\WINDOWS\System32 folder
Open System32 folder and locate the file ateiua.exe.
"Don't delete it yet" , just leave the System32-folder open so you can see the bad file.

Now run APT.exe.  Locate the process ateiua.exe.  Select this process and click Kill 3.

Then immediately return to  your System32 folder.  Delete ateiua.exe.

Close out the System32 folder and return to Desktop

# Open the folder dsrfix

    * Double click on the dsrfix batch file( the one with the little gear in it )
    * Once dsrfix has completed it will close on its own

==Open Windows CleanUp!>>START>>programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files
DECLINE to Log off or Restart when scan is done.

Go to START>>>RUN>>>type in services.msc
Hit OK
In the next window, look on the right hand side for this service
name---- System Startup Service

Double click on it--- STOP the service--If running
In the drop down menu, change the startup type to Disabled

Double-click on nailfix.exe.  Click "Next" in the setup, then make sure "Run Nailfix" is checked and click "Finish".  Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

Afterwards
Do another scan with Hijackthis and put a check next to these entries:
All may not be found, fix what you see

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O4 - HKLM\..\Run: [nvzsjwo] C:\WINDOWS\system32\ateiua.exe r
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run

O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


After you have ticked the above entries, close All other open windows, i
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis

Run Killbox.exe.

* Select "Delete on Reboot".

* Copy the file names below to the clipboard by highlighting ALL of them then press CTRL + C

Killbox paths to file names between dotted lines
=======================================

C:\WINDOWS\system32\lsddsl.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\svcproc.exe
C:\WINDOWS\abiuninst.htm


==================================================

* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. If your computer does not restart automatically, please restart it manually.
Don't worry about any file not found messages

Back in Windows

Run Hijackthis again and Fix checked any of those entries I asked you to fix earlier if they still exist

Can you do the following, I usually leave this till last but I want you too try it now too shorten the Ewido scan results

I need you too disable System Restore, restart your computer and then reenable system restore
How to Disable and Re-enable System Restore feature

Back in Windows and system Restore reenabled

Can you do the following
Open Ewido, check for updates and download them if any
Run another complete scan and save the results afterwards

Next: From my link below, run an Online Virus scan at Panda's
Choose too scan MyComputer
After the scan is done, if anything is found you will have a choice too Save a report
Please save the report to your desktop

Post the report from Panda's back here
Post the new Report from Ewido's also
Run a new scan with Hijackthis and post a fresh log
Run WPFind again and post the log from it too

NOTE: Remember don't let Microsoft AntiSpyware Interfere
EDIT
Dang, I missed a file to kill with Killbox, not to worry, we'll get it later if still around
« Last Edit: August 30, 2005, 11:53:51 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #22 on: August 30, 2005, 11:14:25 PM »
I may not see the results of these scan until tomorrow
But, after you post all the required logs, can you again try not too Restart your computer

We're close to killing this thing  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #23 on: August 31, 2005, 09:58:19 AM »
There is still trouble in this computer because the bad guys are continuing to ask for access to the internet via the ZoneAlarmPro, I am denying this access.  Some reoccuring names are thnall1a.exe,  aurora still gives it a try everyso often, and a new one aurareco.exe is also trying once and a while (all are seeking permission to connect to the internet through ZAP...)

During the step to delet ateiua.exe, I was not fast enough in the delete step and the file name dissolved before my eyes and changed to anther file name.  So , I went back and ran APT again finding the new file and repeated the proces of Kill3 and then got to the delete step before it morphed again, at least I think so....because the name was changing the aphabetized ordering of the files in the system32 folder was also starting to hop around, so it was hard to keep track of what was happening...

Anyway...here is where we stand currently...

Here is HJT file:

Logfile of HijackThis v1.99.1
Scan saved at 10:47:31 AM, on 8/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nitc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\lvefze.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: nitc.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe


Here is the WinPfind:



WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
abetterinternet.com  9/15/2001 3:33:08 AM        3506       C:\WINDOWS\abiuninst.htm
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 6/18/2004 1:18:18 AM        52736      C:\WINDOWS\Nail.exe
UPX!                 12/12/2001 12:01:24 AM      6656       C:\WINDOWS\svcproc.exe
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
UPX!                 11/16/2001 7:59:42 PM       79360      C:\WINDOWS\zbzszynli.exe

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 11/8/2002 5:56:18 PM        28160      C:\WINDOWS\SYSTEM32\DrPMon.dll
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
UPX!                 2/20/2004 6:49:02 PM        77312      C:\WINDOWS\SYSTEM32\Ia1cm.dll
69.59.186.63         8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
209.66.67.134        8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
web-nex              8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
winsync              8/31/2005 1:03:24 AM        10240      C:\WINDOWS\SYSTEM32\jabke.dll
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU
UPX!                 11/20/2004 9:42:24 AM       91136      C:\WINDOWS\SYSTEM32\__delete_on_reboot__lvefze.exe
69.59.186.63         8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
209.66.67.134        8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
web-nex              8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
winsync              8/31/2005 1:03:24 AM        46080      C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     8/31/2005 1:03:02 AM      S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     8/31/2005 10:31:30 AM    H  0          C:\WINDOWS\LastGood\INF\oem7.inf
                     8/31/2005 10:31:30 AM    H  0          C:\WINDOWS\LastGood\INF\oem7.PNF
                     8/31/2005 1:04:18 AM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     8/31/2005 3:01:06 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     8/31/2005 1:03:18 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     8/31/2005 9:03:24 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     8/31/2005 10:43:22 AM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     8/31/2005 10:31:40 AM    H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     8/31/2005 1:03:06 AM     H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     8/30/2005 10:01:40 PM       92160      C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nitc.exe
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
   winsync   C:\WINDOWS\system32\lsddsl.exe reg_run

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = Explorer.exe C:\WINDOWS\Nail.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 8/31/2005 10:46:43 AM


Here is Ewido:


---------------------------------------------------------
 ewido security suite - Scan report
---------------------------------------------------------

 + Created on:         10:19:46 AM, 8/31/2005
 + Report-Checksum:      938E8363

 + Scan result:

   [2032] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Cleaned with backup
   [1076] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1124] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1164] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1148] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1116] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1216] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1268] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1332] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1348] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1388] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1404] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1412] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1436] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1464] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1480] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [1836] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2024] C:\WINDOWS\system32\lvefze.exe -> Trojan.Agent.cp : Cleaned with backup
   [2044] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2068] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [2116] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   [3716] C:\WINDOWS\system32\ssgdfsd.dll -> TrojanDownloader.Qoologic.ac : Error during cleaning
   C:\Documents and Settings\Paul\Cookies\paul@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
   C:\WINDOWS\SYSTEM32\DrPMon.dll -> Trojan.Agent.db : Cleaned with backup
   C:\WINDOWS\SYSTEM32\lvefze.exe -> Trojan.Agent.gp : Cleaned with backup
   C:\WINDOWS\SYSTEM32\pkvyw.dat -> TrojanDownloader.Qoologic.ac : Cleaned with backup


::Report End

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #24 on: August 31, 2005, 08:14:26 PM »
We're not done yet  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

I'm not sure what order you did the last instructions
Ewido claims it removed some bad files but they are still present in your hijackthis log, one as a running process

Can you do the following please

Download and Unzip to desktop NailRemove.zip so you now have NailRemove.bat to desktop
[attachment=326:attachment]
Double click on NailRemove.bat, a window will open and close

Run Killbox.exe.

* Select "Delete on Reboot".

* Copy the file names below to the clipboard by highlighting ALL of them then press CTRL + C

Killbox paths to file names between dotted lines
=======================================

C:\WINDOWS\system32\ssgdfsd.dll
C:\WINDOWS\Nail.exe
C:\WINDOWS\svcproc.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\nitc.exe
C:\WINDOWS\SYSTEM32\__delete_on_reboot__ssgdfsd.dll
C:\WINDOWS\SYSTEM32\__delete_on_reboot__lvefze.exe
C:\WINDOWS\SYSTEM32\jabke.dll
C:\WINDOWS\SYSTEM32\Ia1cm.dll
C:\WINDOWS\SYSTEM32\DrPMon.dll
C:\WINDOWS\zbzszynli.exe
C:\WINDOWS\abiuninst.htm
C:\WINDOWS\system32\lvefze.exe


==================================================

* Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

* Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. If your computer does not restart automatically, please restart it manually.
Don't worry about any file not found messages

Back in Windows
Immediately
Run another scan with Hijackthis and fix checked the following entries
With ALL other windows closed

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe

O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run

O4 - Global Startup: nitc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


Restart your computer

Come back here and run another scan with hijackthis and post a fresh log

Also
Download FindQ.zip and save it to your desktop.

UNZIP the files inside into their own folder called Find Q.
Open the Find Q-folder.
Locate and double-click the Find Q.bat to run it.
Wait until notepad opens and copy and paste the content in your next reply

I see you possibly ran the scan at Panda's also, did you happen to save the report
If so, could you post it too
« Last Edit: August 31, 2005, 08:22:48 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #25 on: August 31, 2005, 10:00:33 PM »
When rebooting both times a windows info box opened and stated that "windows cannot find C:\windows\nail.exe"

when I ran the HJT file I could not check off the two entries:

O4 - Global Startup: nitc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe


because they were not there.


I tried to run Panda but nothing seemed to happen and there was no file to save, it was not clear if it was running a scan or not...

It is hihgly likely that, in the last round,  I performed the tasks in the order that you prescribed

here is the recent HJT file


Logfile of HijackThis v1.99.1
Scan saved at 10:50:21 PM, on 8/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




here is the Find Q result


»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...
 
C:\WINDOWS\SYSTEM32\LSDDSL.EXE
C:\WINDOWS\SYSTEM32\BMOQDBC.EXE
C:\WINDOWS\SYSTEM32\JABKE.DLL
C:\WINDOWS\SYSTEM32\SSGDFSD.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\NITC.EXE
 
»»»»» 2K XP 9X and ME Misc check's...
 
C:\WINDOWS\SYSTEM32\PKVYW.DAT
 
»»»»» 9X and ME check's...

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #26 on: August 31, 2005, 10:27:45 PM »
We're going to try using killbox in a different manner

Save these instructions too a Notepad file
Then close down all other windows including this one
Follow these instructions closely

Run Killbox.exe
So you now have the saved Notepad instructions and Killbox open

# Select the "Delete on Reboot" option.
# Copy/paste the following file to the "Full Path of File to Delete" box in bold:

   C:\WINDOWS\SYSTEM32\LSDDSL.EXE

# Click the red button with a white X on it.
# At the prompt to  "Delete on Reboot" select yes.
# At the prompt to "Reboot Now" select no.
Repeat the above for the following

    C:\WINDOWS\SYSTEM32\BMOQDBC.EXE
C:\WINDOWS\SYSTEM32\JABKE.DLL
C:\WINDOWS\SYSTEM32\SSGDFSD.DLL
C:\DOCUME~1\ALLUSE~1\STARTM~1\PROGRAMS\STARTUP\NITC.EXE


Finally
Copy/paste the following file to the "Full Path of File to Delete" box:

    C:\WINDOWS\SYSTEM32\PKVYW.DAT

# Click the red button with a white X on it.
# At the prompt to "Delete on Reboot" select yes.
# At the prompt to "Reboot Now" select yes.
# Your computer will reboot.

If not please restart manually

Back in Windows

With all other windows closed, run another scan with Hijackthis and fixed checked this entry
O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\lsddsl.exe reg_run

Restart your machine one more time

Back in Windows
Run Hijackthis and post a fresh log

Also run Find Q.bat again, wait for the notepad file to open and post the contents

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #27 on: August 31, 2005, 11:22:53 PM »
here it is:

Logfile of HijackThis v1.99.1
Scan saved at 12:19:53 AM, on 9/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe



FindQ



»»»»» Search by size and name...
»»»»» Files found by this method are not necessarily bad...
»»»»» Example PNGFILT.DLL ctl3d32.dll are windows files...
 
 
»»»»» 2K XP 9X and ME Misc check's...
 
 
»»»»» 9X and ME check's...

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #28 on: August 31, 2005, 11:38:25 PM »
Looks good

Just as some final check
Can I have you do the following
Run WPFind.exe again and post a fresh log from the output

I may not see the log till tomorrow, off to bed soon

If you get a chance, Panda's should of showed a progress bar while scanning your computer and you will see the files being scanned
If you can't get Panda's to run, try one at Kapersky's

The link is in my signature below

Before scanning you may want to disable Norton's Autoprotect so it won't interfere

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.

    * The program will launch and then begin downloading the latest definition files:
    * Once the files have been downloaded click on NEXT
    * Now click on Scan Settings
    * In the scan settings make that the following are selected:
         
    =Scan using the following Anti-Virus database:
               
Extended (if available otherwise Standard)

          =Scan Options:
            Scan Archives
            Scan Mail Bases
[/list]    * Click OK
    * Now under select a target to scan:
            Select My Computer
    * This will program will start and scan your system.
    * The scan will take a while so be patient and let it run.
    * Once the scan is complete it will display if your system has been infected.
          o Now click on the Save as Text button:
    * Save the file to your desktop.

Post the report
« Last Edit: August 31, 2005, 11:40:21 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #29 on: September 01, 2005, 01:28:39 AM »
WinPfind


WARNING: not all files found by this scanner are bad. Consult with a knowledgable person before proceeding.

If you see a message in the titlebar saying "Not responding..." you can ignore it. Windows somethimes displays this message due to the high volume of disk I/O. As long as the hard disk light is flashing, the program is still working properly.

»»»»»»»»»»»»»»»»» Windows OS and Versions »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Product Name: Microsoft Windows XP    Current Build: Service Pack 2    Current Build Number: 2600
Internet Explorer Version: 6.0.2900.2180

»»»»»»»»»»»»»»»»» Checking Selected Standard Folders »»»»»»»»»»»»»»»»»»»»

Checking %SystemDrive% folder...

Checking %ProgramFilesDir% folder...

Checking %WinDir% folder...
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\lpt$vpn.797
UPX!                 1/10/2005 4:17:24 PM        170053     C:\WINDOWS\tsc.exe
PECompact2           8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
qoologic             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
SAHAgent             8/23/2005 1:13:02 PM        15666129   C:\WINDOWS\VPTNFILE.797
UPX!                 2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll
aspack               2/18/2005 6:40:14 PM        1044560    C:\WINDOWS\vsapi32.dll

Checking %System% folder...
UPX!                 11/22/2002 11:21:28 AM      123904     C:\WINDOWS\SYSTEM32\avisynth.dll
UPX!                 9/17/2001 2:20:02 PM        9216       C:\WINDOWS\SYSTEM32\cpuinf32.dll
PEC2                 8/29/2002 7:00:00 AM        41397      C:\WINDOWS\SYSTEM32\DFRG.MSC
UPX!                 11/24/2001 3:31:48 PM       65536      C:\WINDOWS\SYSTEM32\DVDAudio.ax
UPX!                 11/24/2001 3:28:14 PM       86528      C:\WINDOWS\SYSTEM32\DVDVideo.ax
PTech                7/12/2005 5:50:44 PM        520456     C:\WINDOWS\SYSTEM32\LegitCheckControl.DLL
PECompact2           8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2005 9:31:38 PM         1449304    C:\WINDOWS\SYSTEM32\MRT.exe
aspack               8/4/2004 3:56:36 AM         708096     C:\WINDOWS\SYSTEM32\ntdll.dll
Umonitor             8/4/2004 3:56:44 AM         657920     C:\WINDOWS\SYSTEM32\rasdlg.dll
winsync              8/29/2002 7:00:00 AM        1309184    C:\WINDOWS\SYSTEM32\WBDBASE.DEU

Checking %System%\Drivers folder and sub-folders...
PTech                8/4/2004 1:41:38 AM         1309184    C:\WINDOWS\SYSTEM32\drivers\mtlstrm.sys

Items found in C:\WINDOWS\SYSTEM32\drivers\ETC\hosts


Checking the Windows folder and sub-folders for system and hidden files within the last 60 days...
                     9/1/2005 12:19:04 AM      S 2048       C:\WINDOWS\BOOTSTAT.DAT
                     7/27/2005 9:43:58 AM     H  10820      C:\WINDOWS\Help\update.GID
                     9/1/2005 12:21:48 AM     H  335        C:\WINDOWS\SYSTEM32\vsconfig.xml
                     7/8/2005 4:23:18 PM       S 12143      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB893756.cat
                     7/19/2005 7:18:10 PM      S 18913      C:\WINDOWS\SYSTEM32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\KB896727.cat
                     9/1/2005 12:24:36 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.LOG
                     9/1/2005 12:19:16 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SAM.LOG
                     9/1/2005 12:29:12 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SECURITY.LOG
                     9/1/2005 1:19:54 AM      H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.LOG
                     9/1/2005 12:24:24 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.LOG
                     8/11/2005 3:01:34 AM     H  1024       C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
                     9/1/2005 12:19:06 AM     H  6          C:\WINDOWS\Tasks\SA.DAT
                     8/19/2005 12:43:54 PM    HS 113        C:\WINDOWS\Temp\History\History.IE5\desktop.ini
                     8/19/2005 12:43:54 PM    HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\1T8AO7D3\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8DQ78PUJ\desktop.ini
                     8/19/2005 5:10:16 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\8XUVGXIJ\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\DQF1XA02\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\FACFJXWH\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KL0ZK34V\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KP6ZWT2J\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\KPQZ4PAR\desktop.ini
                     8/19/2005 5:10:18 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\OHERKTYF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\QL0BML25\desktop.ini
                     8/19/2005 5:05:10 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UMB9DBLF\desktop.ini
                     8/23/2005 6:01:06 PM     HS 67         C:\WINDOWS\Temp\Temporary Internet Files\Content.IE5\UPD2RMD8\desktop.ini

Checking for CPL files...
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\access.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         549888     C:\WINDOWS\SYSTEM32\appwiz.cpl
Broadcom Corporation           5/8/2003 9:25:18 PM         815104     C:\WINDOWS\SYSTEM32\B57exp.cpl
Broadcom Corporation           6/3/2003 12:38:44 PM        94208      C:\WINDOWS\SYSTEM32\BCMSM.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         110592     C:\WINDOWS\SYSTEM32\bthprops.cpl
FotoNation inc.                3/26/1998 2:01:34 PM        27136      C:\WINDOWS\SYSTEM32\camcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         135168     C:\WINDOWS\SYSTEM32\desk.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         80384      C:\WINDOWS\SYSTEM32\firewall.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         155136     C:\WINDOWS\SYSTEM32\hdwwiz.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\igfxcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         358400     C:\WINDOWS\SYSTEM32\inetcpl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         129536     C:\WINDOWS\SYSTEM32\intl.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         380416     C:\WINDOWS\SYSTEM32\irprops.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         68608      C:\WINDOWS\SYSTEM32\joy.cpl
Sun Microsystems               12/28/2003 6:43:24 PM       53352      C:\WINDOWS\SYSTEM32\jpicpl32.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        187904     C:\WINDOWS\SYSTEM32\MAIN.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         618496     C:\WINDOWS\SYSTEM32\mmsys.cpl
Kristal Studio                 3/2/2001 10:39:28 PM        121856     C:\WINDOWS\SYSTEM32\Mp3cnfg.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        35840      C:\WINDOWS\SYSTEM32\NCPA.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         25600      C:\WINDOWS\SYSTEM32\netsetup.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         257024     C:\WINDOWS\SYSTEM32\nusrmgr.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         32768      C:\WINDOWS\SYSTEM32\odbccp32.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         114688     C:\WINDOWS\SYSTEM32\powercfg.cpl
Apple Computer, Inc.           4/8/2004 2:12:42 PM         323072     C:\WINDOWS\SYSTEM32\QuickTime.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         298496     C:\WINDOWS\SYSTEM32\sysdm.cpl
Microsoft Corporation          8/29/2002 7:00:00 AM        28160      C:\WINDOWS\SYSTEM32\TELEPHON.CPL
Microsoft Corporation          8/4/2004 3:56:58 AM         94208      C:\WINDOWS\SYSTEM32\timedate.cpl
Microsoft Corporation          8/4/2004 3:56:58 AM         148480     C:\WINDOWS\SYSTEM32\wscui.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\wuaucpl.cpl
Microsoft Corporation          5/26/2005 4:16:30 AM        174360     C:\WINDOWS\SYSTEM32\DLLCACHE\wuaucpl.cpl
Intel Corporation              4/7/2003 2:14:30 AM         94208      C:\WINDOWS\SYSTEM32\ReinstallBackups\0000\DriverFiles\igfxcpl.cpl

»»»»»»»»»»»»»»»»» Checking Selected Startup Folders »»»»»»»»»»»»»»»»»»»»»

Checking files in %ALLUSERSPROFILE%\Startup folder...
                     1/20/2004 10:18:02 PM       950        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DESKTOP.INI
                     1/20/2004 9:00:52 PM        1770       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
                     5/23/2004 6:15:04 PM        1798       C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microtek Scanner Finder.lnk
                     1/20/2004 9:51:36 PM        782        C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ZoneAlarm Pro.lnk

Checking files in %ALLUSERSPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\All Users\Application Data\DESKTOP.INI

Checking files in %USERPROFILE%\Startup folder...
                     9/3/2002 11:00:00 AM     HS 84         C:\Documents and Settings\Paul\Start Menu\Programs\Startup\DESKTOP.INI

Checking files in %USERPROFILE%\Application Data folder...
                     9/3/2002 10:50:46 AM     HS 62         C:\Documents and Settings\Paul\Application Data\DESKTOP.INI
                     11/19/2004 11:41:36 AM      61408      C:\Documents and Settings\Paul\Application Data\GDIPFONTCACHEV1.DAT

»»»»»»»»»»»»»»»»» Checking Selected Registry Keys »»»»»»»»»»»»»»»»»»»»»»»

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
   SV1    =

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]

[HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers]
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With
   {09799AFB-AD67-11d1-ABCD-00C04FC30936}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\Open With EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_CLASSES_ROOT\*\shellex\ContextMenuHandlers\{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
   Start Menu Pin    = %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\LDVPMenu
   {BDA77241-42F6-11d0-85E2-00AA001FE28C}    = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\EncryptionMenu
   {A470F8CF-A1E8-4f65-8335-227475AA5C46}    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Offline Files
   {750fdf0e-2a26-11d1-a3ea-080036587f03}    = %SystemRoot%\System32\cscui.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\Sharing
   {f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}    = ntshrui.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{0D2E74C4-3C34-11d2-A27E-00C04FC30871}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F01-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{24F14F02-7B1C-11d1-838f-0000F80461CF}
    = %SystemRoot%\system32\SHELL32.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{66742402-F9B9-11D1-A202-0000F81FEDEE}
    = %SystemRoot%\system32\SHELL32.dll

[HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{4D5C8C25-D075-11d0-B416-00C04FB90376}
   &Tip of the Day = %SystemRoot%\System32\shdocvw.dll
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{FE54FA40-D68C-11d2-98FA-00C0F0318AFE}
   Real.com = C:\WINDOWS\System32\Shdocvw.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
   MenuText    = Sun Java Console   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45}
   ButtonText    = AIM   : C:\Program Files\AIM\aim.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}
   ButtonText    = PartyPoker.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
   ButtonText    = Real.com   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{E023F504-0C5A-4750-A1E7-A9046DEA8A21}
   ButtonText    = MoneySide   :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
   ButtonText    = Messenger   : C:\Program Files\Messenger\msmsgs.exe

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Explorer Bars]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar]
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser
   {01E04581-4EEE-11D0-BFE9-00AA005B4383} = &Address   : %SystemRoot%\System32\browseui.dll
   {0E5CBF21-D15F-11D0-8301-00AA005B4383} = &Links   : %SystemRoot%\system32\SHELL32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   IgfxTray   C:\WINDOWS\System32\igfxtray.exe
   HotKeysCmds   C:\WINDOWS\System32\hkcmd.exe
   BCMSMMSG   BCMSMMSG.exe
   dla   C:\WINDOWS\system32\dla\tfswctrl.exe
   StorageGuard   "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
   PCMService   "C:\Program Files\Dell\Media Experience\PCMService.exe"
   TkBellExe   "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
   mmtask   c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
   DwlClient   C:\Program Files\Common Files\Dell\EUSW\Support.exe
   vptray   C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
   HPDJ Taskbar Utility   C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
   HP Component Manager   "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
   HP Software Update   "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
   DeviceDiscovery   C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
   iTunesHelper   C:\Program Files\iTunes\iTunesHelper.exe
   QuickTime Task   "C:\Program Files\QuickTime\qttask.exe" -atboottime
   PinnacleDriverCheck   C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
   NeroFilterCheck   C:\WINDOWS\system32\NeroCheck.exe
   gcasServ   "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
   IMAIL   Installed = 1
   MAPI   Installed = 1
   MSFS   Installed = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
   Sonic RecordNow!   
   MSMSGS   "C:\Program Files\Messenger\msmsgs.exe" /background
   ctfmon.exe   C:\WINDOWS\system32\ctfmon.exe
   PhotoShow Deluxe Media Manager   C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum
   {BDEADF00-C265-11D0-BCED-00A0C90AB50F} = C:\PROGRA~1\COMMON~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
   {6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} =
   {0DF44EAA-FF21-4412-828E-260A8728E7F1} =


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Ratings

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
   dontdisplaylastusername   0
   legalnoticecaption   
   legalnoticetext   
   shutdownwithoutlogon   1
   undockwithoutlogon   1


[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies]

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
   NoDriveTypeAutoRun   145


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
   PostBootReminder                  {7849596a-48ea-486e-8937-a2a3009f31a9} = %SystemRoot%\system32\SHELL32.dll
   CDBurn                            {fbeb8a05-beee-4442-804e-409d6c4515e9} = %SystemRoot%\system32\SHELL32.dll
   WebCheck                          {E6FB5E20-DE35-11CF-9C87-00AA005127ED} = %SystemRoot%\System32\webcheck.dll
   SysTray                           {35CEC8A3-2BE6-11D2-8773-92E220524153} = C:\WINDOWS\System32\stobject.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   UserInit   = C:\WINDOWS\system32\userinit.exe,
   Shell      = explorer.exe
   System      =

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain
    = crypt32.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet
    = cryptnet.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll
    = cscdll.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy
    = sclgntfy.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn
    = WlNotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon
    = wlnotify.dll

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif
    = wzcdlg.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Your Image File Name Here without a path
   Debugger = ntsd -d

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
   AppInit_DLLs   


»»»»»»»»»»»»»»»»»»»»»»»» Scan Complete »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
WinPFind v1.3.1   - Log file written to "WinPFind.Txt" in the WinPFind folder.
Scan completed on 9/1/2005 1:23:06 AM



Kaspersky  scan



-------------------------------------------------------------------------------
 KASPERSKY ON-LINE SCANNER REPORT
 Thursday, September 01, 2005 02:27:06
 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
 Kaspersky On-line Scanner version: 5.0.67.0
 Kaspersky Anti-Virus database last update:  1/09/2005
 Kaspersky Anti-Virus database records: 146498
-------------------------------------------------------------------------------

Scan Settings:
   Scan using the following antivirus database: extended
   Scan Archives: true
   Scan Mail Bases: true

Scan Target - My Computer:
   A:\
   C:\
   D:\
   E:\

Scan Statistics:
   Total number of scanned objects: 102613
   Number of viruses found: 10
   Number of infected objects: 31
   Number of suspicious objects: 0
   Duration of the scan process: 3063 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\05080000.VBN   Infected: not-a-virus:AdWare.Sahat.w
C:\Documents and Settings\All Users\Desktop\nailfix\Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix\Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix.exe/l2mfix/Process.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Documents and Settings\Paul\Desktop\l2mfix.exe   Infected: not-a-virus:RiskTool.Win32.Processor.20
C:\Program Files\Microsoft AntiSpyware\Quarantine\4163916C-5E58-4E33-8640-7613C1\FC443902-C7F7-4CCC-BFA6-41B0CF   Infected: Trojan-Downloader.Win32.Qoologic.aa
C:\Program Files\Microsoft AntiSpyware\Quarantine\83A9F9FA-6FBD-43BB-A617-7624E8\B7ED67A5-5E29-4371-8AC3-4F68F4   Infected: Trojan-Downloader.Win32.Qoologic.aa
C:\Program Files\Microsoft AntiSpyware\Quarantine\D17E3654-C1BC-4F33-AE54-CE16EF\7DC7882A-F408-4B0C-AE14-B62B96   Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000005.dll   Infected: Trojan.Win32.Agent.db
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000010.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000011.exe   Infected: Trojan.Win32.Agent.gp
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000012.exe   Infected: not-a-virus:AdWareBetterInternet.t
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000013.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000014.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000017.exe   Infected: not-a-virus:AdWare.BetterInternet
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000021.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000035.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000036.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000037.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000042.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000054.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000055.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000056.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000057.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000068.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000069.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000070.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000071.dll   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP1\A0000072.exe   Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\WINDOWS\SYSTEM32\InstallerV4.exe/data0001   Infected: not-a-virus:AdWare.SafeSurfing.o
C:\WINDOWS\SYSTEM32\InstallerV4.exe   Infected: not-a-virus:AdWare.SafeSurfing.o

Scan process completed.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #30 on: September 01, 2005, 08:05:44 PM »
Delete the files if present

C:\WINDOWS\SYSTEM32\InstallerV4.exe/data0001
C:\WINDOWS\SYSTEM32\InstallerV4.exe

If you can't remove them in Normal mode Use Killbox to delete them on Reboot

Afterwards

We must clean your System Restore again
Please disable system restore and restart your computer and reenable system restore

How's everything running?

You should set up protection against future attacks
SpywareBlaster 3.4 by JavaCool
*Will block bad ActiveX Controls
*Block Malevolent cookies in Internet Explorer and Firefox
*Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates and then click the "Enable all protection"

IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
Here is a tutorial and download link
TUTORIAL==Link to Tutorial
Download link

With both, Check for updates every couple of weeks
Keep the link to IE-Spyad bookmarked so you can check for updates
SpywareBlaster, after every update just simply click the "enable all protection"

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #31 on: September 01, 2005, 09:59:55 PM »
guestolo:

I found and deleted this file:
C:\WINDOWS\SYSTEM32\InstallerV4.exe
but the other one was not there.  

I did the system restore disable and reboot and reenabled sys restore.

I will download and use the spyware products you suggest.

In passing, I found out the problem with the inability to boot up in safe mode.  Basically, it arises from an older version of Nero 6.0 and its component InCD...After updating this software to a recent version, the safemode boot problem goes away...This is a known issue:

"IRQ_NOT_LESS_OR_EQUAL STOP: 0x0000000A can be caused by Nero InCD 4300. A side effect is that, very strangely, you cannot boot in safe mode, but you can boot in normal mode. You can try to update InCD to the latest version. There are conflicting reports about version 4303. If you keep having the problem, uninstall the program altogether."

Finally, I want to thank you for the excellent and concientious job you are doing here on this site.  Very remarkable that you can walk us through these minefields without a complete disaster taking place.

Thank you.  I think all is well.

Paul

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #32 on: September 01, 2005, 10:12:43 PM »
THANKS Paul for the Info on INCD  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
You know, I saw Incd in your log and thought it may be the problem, but I wasn't sure

So I thought we should just try and tackle everything in Normal mode
and deal with the safe mode problem later

Can you do something however
Check for updates with Ad-Aware and run a scan to ensure it comes clean

Also, when you get a chance, check for updates with Nortons and run a scan
Are you ready to dump Symantec's Corporate?  

If so, AVG 7 or AVAST both have free editions that are quite good
Don't run more than one AV on your computer however, more than one can cause a conflict
If you need a link let me know

I'll leave this topic open for a couple of days, after which
Would you mind returning and post a fresh hijackthis log

Just want to make sure it's still clean
I don't see any problems, but if something returns I know we can get you into safe mode now  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/biggrin.gif\' class=\'bbc_emoticon\' alt=\':D\' />

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #33 on: September 01, 2005, 11:01:13 PM »
oops!

I just updated and ran Adaware and there were 46 critical objects...Things like VX2  and browser hijack attempts listed.

I checked off the items and they were deleted by adaware...

here is the 9-1-05 Quaratine log from Ad-Aware:

ArchiveData(auto-quarantine- 2005-09-01 23-52-42.bckp)
Referencefile : SE1R64 31.08.2005
======================================================

MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU FileReference : C:\Documents and Settings\Paul\Application Data\microsoft\office\recent\directions.LNK
obj[1]=MRU FileReference : C:\Documents and Settings\Paul\recent\directions.lnk
obj[2]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\adobe\adobe acrobat\5.0\avgeneral\crecentfiles\c1
obj[3]=MRU FileReference : C:\Documents and Settings\Paul\recent\filefindQ.txt.lnk
obj[4]=MRU RegReference : software\microsoft\directdraw\mostrecentapplication name
obj[5]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\internet explorer download directory
obj[6]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\microsoft management console\recent file list
obj[7]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru\5603
obj[8]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru\5604
obj[9]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[10]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.doc
obj[11]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.log
obj[12]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.pdf
obj[13]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
obj[14]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\.zip
obj[15]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs\Folder
obj[16]=MRU FileReference : C:\Documents and Settings\Paul\recent\Scan report_20050831.txt.lnk
obj[17]=MRU RegReference : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\runmru
obj[18]=MRU FileReference : C:\Documents and Settings\Paul\recent\software stuff.lnk
obj[19]=MRU FileReference : C:\Documents and Settings\Paul\recent\Spywarefrom the techguide.doc.lnk
obj[20]=MRU FileReference : C:\Documents and Settings\Paul\recent\WinPFind.lnk
obj[21]=MRU FileReference : C:\Documents and Settings\Paul\recent\WinPFind.Txt.lnk
obj[22]=MRU FileReference : C:\Documents and Settings\Paul\recent\~$ywarefrom the techguide.doc.lnk

VX2
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[13]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3n5trMsgSDisp"
obj[14]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky1S"
obj[15]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky2S"
obj[16]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky3S"
obj[17]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUs3t5icky4S"
obj[18]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC1o3d5eOfSFinalAd"
obj[19]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3i5m7eOfSFinalAd"
obj[20]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUD3s5tSSEnd"
obj[21]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AU3N5a7tionSCode"
obj[22]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUP3D5om"
obj[23]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSCheckSIn"
obj[24]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSMots"
obj[25]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUM3o5deSSync"
obj[26]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSCab"
obj[27]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSEx"
obj[28]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3n5ProgSLstest"
obj[29]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3n5tFyl"
obj[30]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3a5stMotsSDay"
obj[31]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3a5stSSChckin"
obj[32]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUB3D5om"
obj[33]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUE3v5nt"
obj[34]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSBath"
obj[35]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUT3h5rshSysSInf"
obj[36]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUL3n5Title"
obj[37]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUC3u5rrentSMode"
obj[38]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUI3g5noreS"
obj[39]=RegValue : S-1-5-21-31632964-1887330575-3875628783-1009\software\aurora "AUS3t5atusOfSInst"
obj[54]=Regkey : system\controlset001\control\print\monitors\zepmon
obj[55]=Regkey : system\currentcontrolset\control\print\monitors\zepmon
obj[56]=RegValue : software\microsoft\internet explorer\toolbar\webbrowser "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
obj[57]=RegData : software\microsoft\windows nt\currentversion\winlogon "Shell"

POSSIBLE BROWSER HIJACK ATTEMPT
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[40]=Regkey : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1
obj[41]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "DisplayName"
obj[42]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "URLInfoAbout"
obj[43]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Publisher"
obj[44]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "HelpLink"
obj[45]=RegValue : Software\Microsoft\Windows\CurrentVersion\Uninstall\abi-1 "Contact"

TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[46]=IECache Entry : Cookie:[email protected]/cgi-bin
obj[47]=IECache Entry : Cookie:[email protected]/
obj[48]=IECache Entry : Cookie:[email protected]/
obj[49]=IECache Entry : Cookie:[email protected]/
obj[50]=IECache Entry : Cookie:[email protected]/
obj[51]=IECache Entry : Cookie:[email protected]/
obj[52]=IECache Entry : Cookie:[email protected]/
obj[53]=IECache Entry : Cookie:[email protected]/

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #34 on: September 01, 2005, 11:14:00 PM »
That wasn't the full report from Ad-Aware

Can I suggest that you do the following

If you haven't restarted your computer since fixing the Criticals in Ad-Aware
Restart now

Next
Run Ad-Aware
Click on Add-ons in the lefthand column. Select VX2 Cleaner V2.0 and click Run Tool. Click "OK", then, if something is found, click "Clean" as in the directions given. Click "Close", and exit Ad-Aware.
If something is found
Restart the computer again

Back in Windows run a Full system scan with Ad-Aware

If nothing is found by VX2 Cleaner V2.0
Don't bother restarting the computer, but
Run the scan with Ad-Aware anyways
When the scan is complete

Click SHOW LOGFILE
Right click in the results pane and choose SELECT ALL
Then right click and choose Copy to Clipboard
Come back here and in your reply box
Use Ctrl + V on your keyboard to paste the results of the scan back here

Could I get you to run a fresh hijackthis scan and post the log too

EDIT>>Sorry, just realized you posted the quarantine list
Ad-Aware cleaned out some orphaned registry entries
The MRU's are the Most recently used list, not to worry
But do what I posted above and get back to me
« Last Edit: September 01, 2005, 11:16:49 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #35 on: September 01, 2005, 11:48:36 PM »
vx2 was clean

here is the logfile from adaware


Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, September 02, 2005 12:37:30 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R64 31.08.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):5 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


9-2-2005 12:37:30 AM - Scan started. (Smart mode)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
    FilePath           : \SystemRoot\System32\
    ProcessID          : 596
    ThreadCreationTime : 9-2-2005 4:33:11 AM
    BasePriority       : Normal


#:2 [csrss.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 664
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal


#:3 [winlogon.exe]
    FilePath           : \??\C:\WINDOWS\system32\
    ProcessID          : 688
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : High


#:4 [services.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 732
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Services and Controller app
    InternalName       : services.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : services.exe

#:5 [lsass.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 744
    ThreadCreationTime : 9-2-2005 4:33:13 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : LSA Shell (Export Version)
    InternalName       : lsass.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : lsass.exe

#:6 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 900
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:7 [svchost.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 976
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:8 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1068
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:9 [incdsrv.exe]
    FilePath           : C:\Program Files\Ahead\InCD\
    ProcessID          : 1092
    ThreadCreationTime : 9-2-2005 4:33:14 AM
    BasePriority       : Normal
    FileVersion        : 4, 3, 20, 1
    ProductVersion     : 4, 3, 20, 1
    ProductName        : Nero AG incdsrv
    CompanyName        : Nero AG
    FileDescription    : incdsrv
    InternalName       : incdsrv
    LegalCopyright     : Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
    LegalTrademarks    : InCD is a trademark of Nero AG
    OriginalFilename   : incdsrv.exe

#:10 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1224
    ThreadCreationTime : 9-2-2005 4:33:18 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:11 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1344
    ThreadCreationTime : 9-2-2005 4:33:18 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:12 [spoolsv.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 1512
    ThreadCreationTime : 9-2-2005 4:33:20 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion     : 5.1.2600.2696
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Spooler SubSystem App
    InternalName       : spoolsv.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : spoolsv.exe

#:13 [defwatch.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 1644
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Norton AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Virus Definition Daemon
    InternalName       : DefWatch
    LegalCopyright     : Copyright © 1998 Symantec Corporation
    OriginalFilename   : DefWatch.exe

#:14 [ewidoctrl.exe]
    FilePath           : C:\Program Files\ewido\security suite\
    ProcessID          : 1672
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 3, 0, 0, 1
    ProductVersion     : 3, 0, 0, 1
    ProductName        : ewido control
    CompanyName        : ewido networks
    FileDescription    : ewido control
    InternalName       : ewido control
    LegalCopyright     : Copyright © 2004
    OriginalFilename   : ewidoctrl.exe

#:15 [mdm.exe]
    FilePath           : C:\Program Files\Common Files\Microsoft Shared\VS7Debug\
    ProcessID          : 1704
    ThreadCreationTime : 9-2-2005 4:33:28 AM
    BasePriority       : Normal
    FileVersion        : 7.00.9064.9150
    ProductVersion     : 7.00.9064.9150
    ProductName        : Microsoft Development Environment
    CompanyName        : Microsoft Corporation
    FileDescription    : Machine Debug Manager
    InternalName       : mdm.exe
    LegalCopyright     : Copyright © Microsoft Corp. 1997-2000
    OriginalFilename   : mdm.exe

#:16 [rtvscan.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 1880
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Symantec AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec AntiVirus
    LegalCopyright     : Copyright © Symantec Corporation 1991-2003

#:17 [svchost.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1924
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Generic Host Process for Win32 Services
    InternalName       : svchost.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : svchost.exe

#:18 [vsmon.exe]
    FilePath           : C:\WINDOWS\SYSTEM32\ZoneLabs\
    ProcessID          : 1968
    ThreadCreationTime : 9-2-2005 4:33:31 AM
    BasePriority       : Normal
    FileVersion        : 4.0.123.012
    ProductVersion     : 4.0.123.012
    ProductName        : TrueVector Service
    CompanyName        : Zone Labs Inc.
    FileDescription    : TrueVector Service
    InternalName       : vsmon
    LegalCopyright     : Copyright © 1998-2003, Zone Labs Inc.
    OriginalFilename   : vsmon.exe

#:19 [explorer.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 1856
    ThreadCreationTime : 9-2-2005 4:33:42 AM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Windows Explorer
    InternalName       : explorer
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : EXPLORER.EXE

#:20 [alg.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 524
    ThreadCreationTime : 9-2-2005 4:33:43 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Application Layer Gateway Service
    InternalName       : ALG.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : ALG.exe

#:21 [hkcmd.exe]
    FilePath           : C:\WINDOWS\System32\
    ProcessID          : 1420
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        : 3,0,0,2104
    ProductVersion     : 7,0,0,2104
    ProductName        : Intel® Common User Interface
    CompanyName        : Intel Corporation
    FileDescription    : hkcmd Module
    InternalName       : HKCMD
    LegalCopyright     : Copyright 1999-2003, Intel Corporation
    OriginalFilename   : HKCMD.EXE

#:22 [bcmsmmsg.exe]
    FilePath           : C:\WINDOWS\
    ProcessID          : 1776
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        :  3.5.25 08/27/2003 20:04:35
    ProductVersion     :  3.5.25 08/27/2003 20:04:35
    ProductName        : BCM Modem Messaging Applet
    CompanyName        : Broadcom Corporation
    FileDescription    : Modem Messaging Applet
    InternalName       : smdmstat.exe
    LegalCopyright     : Copyright © Broadcom Corporation 1998-2000
    OriginalFilename   : smdmstat.exe

#:23 [sgtray.exe]
    FilePath           : C:\Program Files\Common Files\Sonic\Update Manager\
    ProcessID          : 1820
    ThreadCreationTime : 9-2-2005 4:33:45 AM
    BasePriority       : Normal
    FileVersion        : 1.01.11a
    CompanyName        : Sonic Solutions
    FileDescription    : Sonic Update Manager
    LegalCopyright     : Copyright © 2002 Sonic Solutions

#:24 [pcmservice.exe]
    FilePath           : C:\Program Files\Dell\Media Experience\
    ProcessID          : 2088
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 1.0.0826
    ProductVersion     : 1.0.0826
    ProductName        : PCM2Launcher Application
    CompanyName        : CyberLink Corp.
    FileDescription    : PowerCinema Resident Program for Dell
    InternalName       : PowerCinema Resident Program for Dell
    LegalCopyright     : Copyright c 2003 CyberLink Corp.
    OriginalFilename   : PCM2Launcher.EXE

#:25 [realsched.exe]
    FilePath           : C:\Program Files\Common Files\Real\Update_OB\
    ProcessID          : 2112
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 0.1.0.1622
    ProductVersion     : 0.1.0.1622
    ProductName        : RealOne Player (32-bit)
    CompanyName        : RealNetworks, Inc.
    FileDescription    : RealNetworks Scheduler
    InternalName       : schedapp
    LegalCopyright     : Copyright © RealNetworks, Inc. 1995-2002
    LegalTrademarks    : RealAudio(tm) is a trademark of RealNetworks, Inc.
    OriginalFilename   : realsched.exe

#:26 [mmtask.exe]
    FilePath           : C:\Program Files\MusicMatch\MusicMatch Jukebox\
    ProcessID          : 2128
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 1.0.0.1
    ProductVersion     : 1.0.0.1
    ProductName        : TODO: <Product name>
    CompanyName        : TODO: <Company name>
    FileDescription    : TODO: <File description>
    InternalName       : mmtask.exe
    LegalCopyright     : TODO: © <Company name>.  All rights reserved.
    OriginalFilename   : mmtask.exe

#:27 [support.exe]
    FilePath           : C:\Program Files\Common Files\Dell\EUSW\
    ProcessID          : 2136
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 2, 0, 0, 34
    ProductVersion     : 1, 0, 0, 1
    ProductName        : Dell Support
    CompanyName        : Dell
    FileDescription    : Support
    InternalName       : Support
    LegalCopyright     : Copyright © 2002
    OriginalFilename   : Support.exe

#:28 [vptray.exe]
    FilePath           : C:\PROGRA~1\SYMANT~1\SYMANT~1\
    ProcessID          : 2144
    ThreadCreationTime : 9-2-2005 4:33:46 AM
    BasePriority       : Normal
    FileVersion        : 8.1.0.825
    ProductVersion     : 8.1.0.825
    ProductName        : Symantec AntiVirus
    CompanyName        : Symantec Corporation
    FileDescription    : Symantec AntiVirus
    LegalCopyright     : Copyright © Symantec Corporation 1991-2003

#:29 [hpztsb09.exe]
    FilePath           : C:\WINDOWS\System32\spool\drivers\w32x86\3\
    ProcessID          : 2152
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 2.236.2.0
    ProductVersion     : 2.236.2.0
    ProductName        : HP DeskJet
    CompanyName        : HP
    LegalCopyright     : Copyright © Hewlett-Packard Company 1999-2003

#:30 [hpcmpmgr.exe]
    FilePath           : C:\Program Files\HP\hpcoretech\
    ProcessID          : 2180
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 2.1.1
    ProductVersion     : 2.1.1
    ProductName        : hp coretech  (COmponent REuse TECHnology)
    CompanyName        : Hewlett-Packard Company
    FileDescription    : HP Framework Component Manager Service
    InternalName       : HPComponentManagerService module
    LegalCopyright     : Copyright © Hewlett-Packard. 2002-2003
    OriginalFilename   : HPCmpMgr.exe

#:31 [hpwuschd2.exe]
    FilePath           : C:\Program Files\Hewlett-Packard\HP Software Update\
    ProcessID          : 2192
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 3, 0, 38, 1
    ProductVersion     : 3, 0, 38, 1
    ProductName        : HP Software Update Application
    CompanyName        : Hewlett-Packard Company
    FileDescription    : hpwuSchd
    InternalName       : hpwuSchd
    LegalCopyright     : Copyright © 2003
    OriginalFilename   : hpwuSchd.exe

#:32 [notifyalert.exe]
    FilePath           : C:\Program Files\Dell\Support\Alert\bin\
    ProcessID          : 2200
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal


#:33 [hpotdd01.exe]
    FilePath           : C:\Program Files\Hewlett-Packard\Digital Imaging\bin\
    ProcessID          : 2208
    ThreadCreationTime : 9-2-2005 4:33:47 AM
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : Hewlett-Packard hpotdd01
    CompanyName        : Hewlett-Packard
    FileDescription    : hpotdd01
    InternalName       : hpotdd01
    LegalCopyright     : Copyright © 2002
    OriginalFilename   : hpotdd01.exe

#:34 [ituneshelper.exe]
    FilePath           : C:\Program Files\iTunes\
    ProcessID          : 2216
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 4.6.0.15
    ProductVersion     : 4.6.0.15
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iTunesHelper Module
    InternalName       : iTunesHelper
    LegalCopyright     : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iTunesHelper.exe

#:35 [qttask.exe]
    FilePath           : C:\Program Files\QuickTime\
    ProcessID          : 2224
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 6.5.1
    ProductVersion     : QuickTime 6.5.1
    ProductName        : QuickTime
    CompanyName        : Apple Computer, Inc.
    InternalName       : QuickTime Task
    LegalCopyright     : © Apple Computer, Inc. 2001-2004
    OriginalFilename   : QTTask.exe

#:36 [ipodservice.exe]
    FilePath           : C:\Program Files\iPod\bin\
    ProcessID          : 2256
    ThreadCreationTime : 9-2-2005 4:33:48 AM
    BasePriority       : Normal
    FileVersion        : 4.6.0.15
    ProductVersion     : 4.6.0.15
    ProductName        : iTunes
    CompanyName        : Apple Computer, Inc.
    FileDescription    : iPodService Module
    InternalName       : iPodService
    LegalCopyright     : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename   : iPodService.exe

#:37 [incd.exe]
    FilePath           : C:\Program Files\Ahead\InCD\
    ProcessID          : 2424
    ThreadCreationTime : 9-2-2005 4:33:50 AM
    BasePriority       : Normal
    FileVersion        : 4, 3, 20, 1
    ProductVersion     : 4, 3, 20, 1
    ProductName        : Nero AG InCD
    CompanyName        : Nero AG
    FileDescription    : InCD
    InternalName       : InCD
    LegalCopyright     : Copyright 1995-2005 Nero AG and its licensors. All Rights Reserved.
    LegalTrademarks    : InCD is a trademark of Nero AG
    OriginalFilename   : InCD.exe

#:38 [ctfmon.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 2448
    ThreadCreationTime : 9-2-2005 4:33:51 AM
    BasePriority       : Normal
    FileVersion        : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 5.1.2600.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : CTF Loader
    InternalName       : CTFMON
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : CTFMON.EXE

#:39 [mssysmgr.exe]
    FilePath           : C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\
    ProcessID          : 2464
    ThreadCreationTime : 9-2-2005 4:33:51 AM
    BasePriority       : Normal
    FileVersion        : 2, 1, 1, 537
    ProductVersion     : 2, 1, 1, 537
    ProductName        : PhotoShow Deluxe
    CompanyName        : Simple Star, Inc.
    FileDescription    : PhotoShow Deluxe Media Manager
    InternalName       : PhotoShow Deluxe Media Manager
    LegalCopyright     : Copyright © 2003 Simple Star, Inc.
    OriginalFilename   : mssysmgr.exe

#:40 [gcasdtserv.exe]
    FilePath           : C:\Program Files\Microsoft AntiSpyware\
    ProcessID          : 2484
    ThreadCreationTime : 9-2-2005 4:33:52 AM
    BasePriority       : Normal
    FileVersion        : 1.00.0615
    ProductVersion     : 1.00.0615
    ProductName        : Microsoft AntiSpyware (Beta 1)
    CompanyName        : Microsoft Corporation
    FileDescription    : Microsoft AntiSpyware Data Service
    InternalName       : gcasDtServ
    LegalCopyright     : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
    LegalTrademarks    : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet(tm) is a trademark of Microsoft Corporation.
    OriginalFilename   : gcasDtServ.exe

#:41 [acrotray.exe]
    FilePath           : C:\Program Files\Adobe\Acrobat 5.0\Distillr\
    ProcessID          : 2556
    ThreadCreationTime : 9-2-2005 4:33:55 AM
    BasePriority       : Normal
    FileVersion        : 5, 0, 0, 0
    ProductVersion     : 5, 0, 0, 0
    ProductName        : AcroTray - Adobe Acrobat Distiller helper application.
    CompanyName        : Adobe Systems Inc.
    FileDescription    : AcroTray
    InternalName       : AcroTray
    LegalCopyright     : Copyright © 2001
    OriginalFilename   : AcroTray.exe

#:42 [scannerfinder.exe]
    FilePath           : C:\Program Files\Microtek\ScanWizard 5\
    ProcessID          : 2772
    ThreadCreationTime : 9-2-2005 4:34:03 AM
    BasePriority       : Normal
    FileVersion        : 1, 0, 0, 1
    ProductVersion     : 1, 0, 0, 1
    ProductName        : SDII Application
    FileDescription    : SDII MFC Application
    InternalName       : SDII
    LegalCopyright     : Copyright © 2000
    OriginalFilename   : SDII.EXE

#:43 [zapro.exe]
    FilePath           : C:\Program Files\Zone Labs\ZoneAlarm\
    ProcessID          : 2784
    ThreadCreationTime : 9-2-2005 4:34:03 AM
    BasePriority       : Normal
    FileVersion        : 4.0.123.012
    ProductVersion     : 4.0.123.012
    ProductName        : ZoneAlarm Pro
    CompanyName        : Zone Labs Inc.
    FileDescription    : ZoneAlarm Pro
    InternalName       : zapro
    LegalCopyright     : Copyright © 1998-2003, Zone Labs Inc.
    OriginalFilename   : zapro.exe

#:44 [iexplore.exe]
    FilePath           : C:\Program Files\Internet Explorer\
    ProcessID          : 2916
    ThreadCreationTime : 9-2-2005 4:34:09 AM
    BasePriority       : Normal
    FileVersion        : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion     : 6.00.2900.2180
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Internet Explorer
    InternalName       : iexplore
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : IEXPLORE.EXE

#:45 [wuauclt.exe]
    FilePath           : C:\WINDOWS\system32\
    ProcessID          : 3080
    ThreadCreationTime : 9-2-2005 4:34:18 AM
    BasePriority       : Normal
    FileVersion        : 5.8.0.2469 built by: lab01_n(wmbla)
    ProductVersion     : 5.8.0.2469
    ProductName        : Microsoft® Windows® Operating System
    CompanyName        : Microsoft Corporation
    FileDescription    : Automatic Updates
    InternalName       : wuauclt.exe
    LegalCopyright     : © Microsoft Corporation. All rights reserved.
    OriginalFilename   : wuauclt.exe

#:46 [ad-aware.exe]
    FilePath           : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
    ProcessID          : 3416
    ThreadCreationTime : 9-2-2005 4:35:28 AM
    BasePriority       : Normal
    FileVersion        : 6.2.0.236
    ProductVersion     : SE 106
    ProductName        : Lavasoft Ad-Aware SE
    CompanyName        : Lavasoft Sweden
    FileDescription    : Ad-Aware SE Core application
    InternalName       : Ad-Aware.exe
    LegalCopyright     : Copyright © Lavasoft AB Sweden
    OriginalFilename   : Ad-Aware.exe
    Comments           : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0



Deep scanning and examining files...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0

Disk Scan Result for C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0

Disk Scan Result for C:\DOCUME~1\Paul\LOCALS~1\Temp\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 0



 MRU List Object Recognized!
    Location:          : C:\Documents and Settings\Paul\recent
    Description        : list of recently opened documents


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\search assistant\acmru
    Description        : list of recent search terms used with the search assistant


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
    Description        : list of recent programs opened


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
    Description        : list of recently saved files, stored according to file extension


 MRU List Object Recognized!
    Location:          : S-1-5-21-31632964-1887330575-3875628783-1009\software\microsoft\windows\currentversion\explorer\recentdocs
    Description        : list of recent documents opened



Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 5

12:40:23 AM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:02:53.703
Objects scanned:87447
Objects identified:0
Objects ignored:0
New critical objects:0




also HJT



Logfile of HijackThis v1.99.1
Scan saved at 12:47:05 AM, on 9/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe




I think/hope all is ok now...


thanks again, guestolo....

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #36 on: September 02, 2005, 08:32:04 AM »
Looks good  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

I'll lock this topic later today if you have no other problems

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline physicsforfun

  • Newbie
  • *
  • Posts: 37
  • Karma: +0/-0
    • View Profile
malware aurora, trojans, etc
« Reply #37 on: September 06, 2005, 06:20:34 PM »
Gestolo,

you had asked that I return in a few days to post another HJT file.


"I'll leave this topic open for a couple of days, after which
Would you mind returning and post a fresh hijackthis log

Just want to make sure it's still clean
I don't see any problems, but if something returns I know we can get you into safe mode now "



So here I am and here is the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 7:07:46 PM, on 9/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Documents and Settings\Paul\Desktop\software stuff\HijackThis adaware etc\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PhotoShow Deluxe Media Manager] C:\PROGRA~1\SIMPLE~1\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: ZoneAlarm Pro.lnk = C:\Program Files\Zone Labs\ZoneAlarm\zapro.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\IEExtension.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {F7A05BAC-9778-410A-9CDE-BFBD4D5D2B7F} (iPIX Media Send Class) - http://216.249.24.60/code/iPIX-ImageWell-ipix.cab
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Hope all is still ok.

Paul

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
malware aurora, trojans, etc
« Reply #38 on: September 06, 2005, 11:47:34 PM »
I merged your topics to this one
I'll reopened this topic  for a couple of days
Your log
Looks good, I can't remember if I asked that you intentionally installed Party Poker
If you did,everything looks good  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Stay safe
« Last Edit: September 07, 2005, 12:18:47 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here