Page 1 of 2 12 LastLast
Results 1 to 10 of 20

Thread: Virtumonde infection

  1. #1
    Member
    Join Date
    Feb 2009
    Posts
    37

    Default Virtumonde infection

    Hello, I recently ran a Spybot scan this morning and it says that I have a Virtumonde infection. My computer hasn't shown any signs of infection other than running a bit slower than normal. I ran ERUNT and the DSS tool and attached the zipped attachment. Thank you for your help!

    Here's the DSS text:

    DDS (Ver_10-03-17.01) - NTFSx86
    Run by ron at 17:59:32.15 on Wed 08/25/2010
    Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1014.482 [GMT -5:00]

    AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
    FW: COMODO Firewall *enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe -k netsvcs
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    svchost.exe
    svchost.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\hphmon05.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    svchost.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\PictureMover\Bin\PictureMover.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe -k imgsvc
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Java\Java Update\jucheck.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\ron\My Documents\Downloads\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
    BHO: AOL Toolbar Launcher: {7c554162-8cb7-45a4-b8f4-8ea1c75885f9} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\googletoolbar3.dll
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\3.1.807.1746\swg.dll
    BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: &Google: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\googletoolbar3.dll
    TB: AIM Toolbar: {de9c389f-3316-41a7-809b-aa305ed9d922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    uRun: [EPSON Stylus CX7400 Series] c:\windows\system32\spool\drivers\w32x86\3\e_faticda.exe /fu "c:\windows\temp\E_S81D.tmp" /EF "HKCU"
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe
    mRun: [igfxtray] c:\windows\system32\igfxtray.exe
    mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
    mRun: [igfxpers] c:\windows\system32\igfxpers.exe
    mRun: [QUICKCARE] c:\program files\qwest\quickcare\bin\sprtcmd.exe /P QUICKCARE
    mRun: [HPHUPD05] c:\program files\hp\{45b6180b-dcab-4093-8ee8-6164457517f0}\hphupd05.exe
    mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
    mRun: [HPHmon05] c:\windows\system32\hphmon05.exe
    mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe
    mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe
    mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [COMODO Internet Security] "c:\program files\comodo\comodo internet security\cfp.exe" -h
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    StartupFolder: c:\docume~1\ron\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pictur~1.lnk - c:\program files\picturemover\bin\PictureMover.exe
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {3369AF0D-62E9-4bda-8103-B4C75499B578} - {DE9C389F-3316-41A7-809B-AA305ED9D922} - c:\program files\aol\aim toolbar 5.0\aoltb.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
    DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab
    DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
    DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://fpdownload.macromedia.com/get/shockwave/cabs/director/sw.cab
    DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} - hxxp://www2.snapfish.com/SnapfishActivia.cab
    DPF: {49232000-16E4-426C-A231-62846947304B} - hxxp://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
    DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - hxxp://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
    DPF: {596AF4AC-40A0-474A-9F86-33F0A90F0FD6} - hxxp://photos.msn.com/resources/neutral/controls/DigWebX2.cab
    DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader3.cab
    DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
    DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150132468906
    DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - hxxp://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
    DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150132521938
    DPF: {6F750202-1362-4815-A476-88533DE61D0C} - hxxp://targetphoto.kodakgallery.com/downloads/BUM/BUM_WIN_IE_2/axofupld.cab
    DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
    DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} - hxxp://web1.shutterfly.com/downloads/Uploader.cab
    DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
    DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} - hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
    Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
    Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
    Notify: avgrsstarter - avgrsstx.dll
    Notify: igfxcui - igfxdev.dll
    AppInit_DLLs: c:\windows\system32\guard32.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
    Hosts: 127.0.0.1 www.spywareinfo.com

    ================= FIREFOX ===================

    FF - ProfilePath - c:\docume~1\ron\applic~1\mozilla\firefox\profiles\92zofaby.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
    FF - prefs.js: browser.startup.homepage - msn.com
    FF - component: c:\program files\avg\avg9\firefox\components\avgssff.dll
    FF - plugin: c:\documents and settings\ron\application data\move networks\plugins\npqmp071505000011.dll
    FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
    FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
    FF - plugin: c:\program files\viewpoint\viewpoint media player\npViewpoint.dll
    FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--p1ai", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbayh7gpa", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.count", 24);
    c:\program files\mozilla firefox\greprefs\all.js - pref("network.buffer.cache.size", 4096);
    c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
    c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
    c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-12-2 216400]
    R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-12-2 29584]
    R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-12-2 243024]
    R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [2010-6-4 229312]
    R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [2010-6-1 25240]
    R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-7-15 308136]
    R2 cmdAgent;COMODO Internet Security Helper Service;c:\program files\comodo\comodo internet security\cmdagent.exe [2010-6-1 1778480]
    R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\viewpoint\common\ViewpointService.exe [2007-10-29 24652]

    =============== Created Last 30 ================

    2010-08-03 23:07:07 5632 ----a-w- c:\windows\system32\ptpusb.dll
    2010-08-03 23:07:03 159232 ----a-w- c:\windows\system32\ptpusd.dll

    ==================== Find3M ====================

    2010-07-27 23:52:37 21372 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-07-27 06:30:35 8462336 ------w- c:\windows\system32\dllcache\shell32.dll
    2010-07-15 14:39:07 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
    2010-07-15 14:39:05 12536 ----a-w- c:\windows\system32\avgrsstx.dll
    2010-07-15 14:38:15 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
    2010-06-30 12:31:35 149504 ----a-w- c:\windows\system32\schannel.dll
    2010-06-30 12:31:35 149504 ------w- c:\windows\system32\dllcache\schannel.dll
    2010-06-24 22:51:58 11077120 ------w- c:\windows\system32\dllcache\ieframe.dll
    2010-06-24 12:22:03 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-06-24 12:22:03 916480 ------w- c:\windows\system32\dllcache\wininet.dll
    2010-06-24 12:22:03 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
    2010-06-24 12:22:02 1210368 ------w- c:\windows\system32\dllcache\urlmon.dll
    2010-06-24 12:22:01 611840 ----a-w- c:\windows\system32\dllcache\mstime.dll
    2010-06-24 12:22:01 5951488 ------w- c:\windows\system32\dllcache\mshtml.dll
    2010-06-24 12:22:01 206848 ----a-w- c:\windows\system32\dllcache\occache.dll
    2010-06-24 12:21:59 599040 ----a-w- c:\windows\system32\dllcache\msfeeds.dll
    2010-06-24 12:21:59 55296 ----a-w- c:\windows\system32\dllcache\msfeedsbs.dll
    2010-06-24 12:21:59 25600 ------w- c:\windows\system32\dllcache\jsproxy.dll
    2010-06-24 12:21:58 247808 ------w- c:\windows\system32\dllcache\ieproxy.dll
    2010-06-24 12:21:58 1986560 ------w- c:\windows\system32\dllcache\iertutil.dll
    2010-06-24 12:21:58 184320 ----a-w- c:\windows\system32\dllcache\iepeers.dll
    2010-06-24 12:21:56 743424 ------w- c:\windows\system32\dllcache\iedvtool.dll
    2010-06-24 12:21:55 387584 ------w- c:\windows\system32\dllcache\iedkcs32.dll
    2010-06-23 13:44:04 1851904 ----a-w- c:\windows\system32\win32k.sys
    2010-06-23 13:44:04 1851904 ------w- c:\windows\system32\dllcache\win32k.sys
    2010-06-23 12:08:09 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
    2010-06-21 15:27:11 354304 ------w- c:\windows\system32\dllcache\srv.sys
    2010-06-18 13:36:12 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
    2010-06-17 14:03:00 80384 ----a-w- c:\windows\system32\iccvid.dll
    2010-06-14 14:31:20 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-06-14 07:41:45 1172480 ----a-w- c:\windows\system32\msxml3.dll
    2010-06-14 07:41:45 1172480 ------w- c:\windows\system32\dllcache\msxml3.dll
    2010-06-02 00:00:52 278288 ----a-w- c:\windows\system32\guard32.dll
    2008-12-11 09:14:00 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008121120081212\index.dat

    ============= FINISH: 18:01:20.50 ===============

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Mdolph15

    Please post next spybot report
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Member
    Join Date
    Feb 2009
    Posts
    37

    Default

    Hi Shaba, I ran a Spybot scan again. Here's the report:

    --- Search result list ---
    Virtumonde: [SBI $0B04958D] User settings (Registry key, nothing done)
    HKEY_USERS\S-1-5-21-540961431-1912937874-3570792479-1006\Software\Microsoft\fias4031


    --- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

    2009-01-26 blindman.exe (1.0.0.8)
    2009-01-26 SDFiles.exe (1.6.1.7)
    2009-01-26 SDMain.exe (1.0.0.6)
    2009-01-26 SDShred.exe (1.0.2.5)
    2009-01-26 SDUpdate.exe (1.6.0.12)
    2009-01-26 SpybotSD.exe (1.6.2.46)
    2009-03-05 TeaTimer.exe (1.6.6.32)
    2006-06-12 unins000.exe (51.41.0.0)
    2009-10-14 unins001.exe (51.49.0.0)
    2009-01-26 Update.exe (1.6.0.7)
    2009-11-04 advcheck.dll (1.6.5.20)
    2007-04-02 aports.dll (2.1.0.0)
    2005-05-31 borlndmm.dll (7.0.4.453)
    2005-05-31 delphimm.dll (7.0.4.453)
    2008-06-14 DelZip179.dll (1.79.11.1)
    2009-01-26 SDHelper.dll (1.6.2.14)
    2008-06-19 sqlite3.dll
    2009-01-26 Tools.dll (2.1.6.10)
    2009-01-16 UninsSrv.dll (1.0.0.0)
    2005-05-31 UnzDll.dll (1.73.1.1)
    2005-05-31 ZipDll.dll (1.73.2.0)
    2010-06-29 Includes\Adware.sbi (*)
    2010-08-24 Includes\AdwareC.sbi (*)
    2010-08-13 Includes\Cookies.sbi (*)
    2009-11-03 Includes\Dialer.sbi (*)
    2010-07-27 Includes\DialerC.sbi (*)
    2010-01-25 Includes\HeavyDuty.sbi (*)
    2009-05-26 Includes\Hijackers.sbi (*)
    2010-07-27 Includes\HijackersC.sbi (*)
    2010-06-29 Includes\iPhone.sbi (*)
    2010-08-02 Includes\Keyloggers.sbi (*)
    2010-08-02 Includes\KeyloggersC.sbi (*)
    2004-11-29 Includes\LSP.sbi (*)
    2010-06-01 Includes\Malware.sbi (*)
    2010-08-24 Includes\MalwareC.sbi (*)
    2010-05-18 Includes\PUPS.sbi (*)
    2010-07-20 Includes\PUPSC.sbi (*)
    2010-01-25 Includes\Revision.sbi (*)
    2009-01-13 Includes\Security.sbi (*)
    2010-07-27 Includes\SecurityC.sbi (*)
    2008-06-03 Includes\Spybots.sbi (*)
    2008-06-03 Includes\SpybotsC.sbi (*)
    2010-06-29 Includes\Spyware.sbi (*)
    2010-07-27 Includes\SpywareC.sbi (*)
    2010-03-08 Includes\Tracks.uti
    2010-08-04 Includes\Trojans.sbi (*)
    2010-07-28 Includes\TrojansC-02.sbi (*)
    2010-07-28 Includes\TrojansC-03.sbi (*)
    2010-07-28 Includes\TrojansC-04.sbi (*)
    2010-08-24 Includes\TrojansC-05.sbi (*)
    2010-08-16 Includes\TrojansC.sbi (*)
    2008-03-04 Plugins\Chai.dll
    2008-03-05 Plugins\Fennel.dll
    2008-02-26 Plugins\Mate.dll
    2007-12-24 Plugins\TCPIPAddress.dll



    --- System information ---
    Windows XP (Build: 2600) Service Pack 3 (5.1.2600)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Security Update (KB979906)
    / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460)
    / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
    / MSXML4SP2: Security update for MSXML4 SP2 (KB936181)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB954430)
    / MSXML4SP2: Security update for MSXML4 SP2 (KB973688)
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458)
    / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723)
    / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs
    / Windows / SP1: Microsoft National Language Support Downlevel APIs
    / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399)
    / Windows Media Player: Security Update for Windows Media Player (KB952069)
    / Windows Media Player: Security Update for Windows Media Player (KB954155)
    / Windows Media Player: Security Update for Windows Media Player (KB968816)
    / Windows Media Player: Security Update for Windows Media Player (KB973540)
    / Windows Media Player: Security Update for Windows Media Player (KB978695)
    / Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
    / Windows Media Player 10: Security Update for Windows Media Player 10 (KB936782)
    / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683)
    / Windows Media Player 11: Security Update for Windows Media Player 11 (KB954154)
    / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398)
    / Windows XP: Security Update for Windows XP (KB923689)
    / Windows XP: Security Update for Windows XP (KB941569)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB2183461)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533)
    / Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB953838)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB956390)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB958215)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB960714)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB961260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB963027)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB969897)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB969897)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB971930)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB971961)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB972260)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB974455)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB976325)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB976662)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB976749)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB978207)
    / Windows XP / SP0: Update for Windows Internet Explorer 8 (KB980182)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB981332)
    / Windows XP / SP0: Security Update for Windows Internet Explorer 8 (KB982381)
    / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP
    / Windows XP / SP3: Windows XP Service Pack 3
    / Windows XP / SP4: Security Update for Windows XP (KB2079403)
    / Windows XP / SP4: Security Update for Windows XP (KB2115168)
    / Windows XP / SP4: Security Update for Windows XP (KB2160329)
    / Windows XP / SP4: Security Update for Windows XP (KB2229593)
    / Windows XP / SP4: Security Update for Windows XP (KB2286198)
    / Windows XP / SP4: Security Update for Windows XP (KB923561)
    / Windows XP / SP4: Security Update for Windows XP (KB938464)
    / Windows XP / SP4: Security Update for Windows XP (KB938464-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB946648)
    / Windows XP / SP4: Security Update for Windows XP (KB950760)
    / Windows XP / SP4: Security Update for Windows XP (KB950762)
    / Windows XP / SP4: Security Update for Windows XP (KB950974)
    / Windows XP / SP4: Security Update for Windows XP (KB951066)
    / Windows XP / SP4: Update for Windows XP (KB951072-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951376)
    / Windows XP / SP4: Security Update for Windows XP (KB951376-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB951698)
    / Windows XP / SP4: Security Update for Windows XP (KB951748)
    / Windows XP / SP4: Update for Windows XP (KB951978)
    / Windows XP / SP4: Security Update for Windows XP (KB952004)
    / Windows XP / SP4: Hotfix for Windows XP (KB952287)
    / Windows XP / SP4: Security Update for Windows XP (KB952954)
    / Windows XP / SP4: Security Update for Windows XP (KB953839)
    / Windows XP / SP4: Security Update for Windows XP (KB954211)
    / Windows XP / SP4: Security Update for Windows XP (KB954459)
    / Windows XP / SP4: Hotfix for Windows XP (KB954550-v5)
    / Windows XP / SP4: Security Update for Windows XP (KB954600)
    / Windows XP / SP4: Security Update for Windows XP (KB955069)
    / Windows XP / SP4: Update for Windows XP (KB955759)
    / Windows XP / SP4: Update for Windows XP (KB955839)
    / Windows XP / SP4: Security Update for Windows XP (KB956391)
    / Windows XP / SP4: Security Update for Windows XP (KB956572)
    / Windows XP / SP4: Security Update for Windows XP (KB956744)
    / Windows XP / SP4: Security Update for Windows XP (KB956802)
    / Windows XP / SP4: Security Update for Windows XP (KB956803)
    / Windows XP / SP4: Security Update for Windows XP (KB956841)
    / Windows XP / SP4: Security Update for Windows XP (KB956844)
    / Windows XP / SP4: Security Update for Windows XP (KB957095)
    / Windows XP / SP4: Security Update for Windows XP (KB957097)
    / Windows XP / SP4: Security Update for Windows XP (KB958644)
    / Windows XP / SP4: Security Update for Windows XP (KB958687)
    / Windows XP / SP4: Security Update for Windows XP (KB958690)
    / Windows XP / SP4: Security Update for Windows XP (KB958869)
    / Windows XP / SP4: Security Update for Windows XP (KB959426)
    / Windows XP / SP4: Security Update for Windows XP (KB960225)
    / Windows XP / SP4: Security Update for Windows XP (KB960715)
    / Windows XP / SP4: Security Update for Windows XP (KB960803)
    / Windows XP / SP4: Security Update for Windows XP (KB960859)
    / Windows XP / SP4: Hotfix for Windows XP (KB961118)
    / Windows XP / SP4: Security Update for Windows XP (KB961371)
    / Windows XP / SP4: Security Update for Windows XP (KB961373)
    / Windows XP / SP4: Security Update for Windows XP (KB961501)
    / Windows XP / SP4: Update for Windows XP (KB967715)
    / Windows XP / SP4: Update for Windows XP (KB968389)
    / Windows XP / SP4: Security Update for Windows XP (KB968537)
    / Windows XP / SP4: Security Update for Windows XP (KB969059)
    / Windows XP / SP4: Security Update for Windows XP (KB969898)
    / Windows XP / SP4: Security Update for Windows XP (KB969947)
    / Windows XP / SP4: Security Update for Windows XP (KB970238)
    / Windows XP / SP4: Security Update for Windows XP (KB970430)
    / Windows XP / SP4: Hotfix for Windows XP (KB970653-v3)
    / Windows XP / SP4: Security Update for Windows XP (KB971468)
    / Windows XP / SP4: Security Update for Windows XP (KB971486)
    / Windows XP / SP4: Security Update for Windows XP (KB971557)
    / Windows XP / SP4: Security Update for Windows XP (KB971633)
    / Windows XP / SP4: Security Update for Windows XP (KB971657)
    / Windows XP / SP4: Update for Windows XP (KB971737)
    / Windows XP / SP4: Security Update for Windows XP (KB972270)
    / Windows XP / SP4: Security Update for Windows XP (KB973346)
    / Windows XP / SP4: Security Update for Windows XP (KB973354)
    / Windows XP / SP4: Security Update for Windows XP (KB973507)
    / Windows XP / SP4: Security Update for Windows XP (KB973525)
    / Windows XP / SP4: Update for Windows XP (KB973687)
    / Windows XP / SP4: Update for Windows XP (KB973815)
    / Windows XP / SP4: Security Update for Windows XP (KB973869)
    / Windows XP / SP4: Security Update for Windows XP (KB973904)
    / Windows XP / SP4: Security Update for Windows XP (KB974112)
    / Windows XP / SP4: Security Update for Windows XP (KB974318)
    / Windows XP / SP4: Security Update for Windows XP (KB974392)
    / Windows XP / SP4: Security Update for Windows XP (KB974571)
    / Windows XP / SP4: Security Update for Windows XP (KB975025)
    / Windows XP / SP4: Security Update for Windows XP (KB975467)
    / Windows XP / SP4: Security Update for Windows XP (KB975560)
    / Windows XP / SP4: Security Update for Windows XP (KB975561)
    / Windows XP / SP4: Security Update for Windows XP (KB975562)
    / Windows XP / SP4: Security Update for Windows XP (KB975713)
    / Windows XP / SP4: Hotfix for Windows XP (KB976098-v2)
    / Windows XP / SP4: Security Update for Windows XP (KB977165)
    / Windows XP / SP4: Security Update for Windows XP (KB977816)
    / Windows XP / SP4: Security Update for Windows XP (KB977914)
    / Windows XP / SP4: Security Update for Windows XP (KB978037)
    / Windows XP / SP4: Security Update for Windows XP (KB978251)
    / Windows XP / SP4: Security Update for Windows XP (KB978262)
    / Windows XP / SP4: Security Update for Windows XP (KB978338)
    / Windows XP / SP4: Security Update for Windows XP (KB978542)
    / Windows XP / SP4: Security Update for Windows XP (KB978601)
    / Windows XP / SP4: Security Update for Windows XP (KB978706)
    / Windows XP / SP4: Hotfix for Windows XP (KB979306)
    / Windows XP / SP4: Security Update for Windows XP (KB979309)
    / Windows XP / SP4: Security Update for Windows XP (KB979482)
    / Windows XP / SP4: Security Update for Windows XP (KB979559)
    / Windows XP / SP4: Security Update for Windows XP (KB979683)
    / Windows XP / SP4: Security Update for Windows XP (KB980195)
    / Windows XP / SP4: Security Update for Windows XP (KB980218)
    / Windows XP / SP4: Security Update for Windows XP (KB980232)
    / Windows XP / SP4: Security Update for Windows XP (KB980436)
    / Windows XP / SP4: Hotfix for Windows XP (KB981793)
    / Windows XP / SP4: Security Update for Windows XP (KB981852)
    / Windows XP / SP4: Security Update for Windows XP (KB981997)
    / Windows XP / SP4: Security Update for Windows XP (KB982214)
    / Windows XP / SP4: Security Update for Windows XP (KB982665)


    --- Startup entries list ---
    Located: HK_LM:Run, Adobe ARM
    command: "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    file: C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    size: 976832
    MD5: 0B232C77D822983397674AEEC9AB59DC

    Located: HK_LM:Run, Adobe Reader Speed Launcher
    command: "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    file: C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
    size: 35760
    MD5: A32B25970003B6ABA027EFF8EEDA12A3

    Located: HK_LM:Run, AppleSyncNotifier
    command: C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    file: C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    size: 47392
    MD5: FD89A30C8A9FF4929ABC5039E6A527A4

    Located: HK_LM:Run, AVG9_TRAY
    command: C:\PROGRA~1\AVG\AVG9\avgtray.exe
    file: C:\PROGRA~1\AVG\AVG9\avgtray.exe
    size: 2065760
    MD5: E9B04FD2921ACE22CA17FA7D5131F491

    Located: HK_LM:Run, COMODO Internet Security
    command: "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    file: C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    size: 2039240
    MD5: E25076570C6CC864043047325AF16F44

    Located: HK_LM:Run, HP Component Manager
    command: "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    file: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    size: 221184
    MD5: C130EAE1DA69AC31208880EF5E0BEC4C

    Located: HK_LM:Run, HPDJ Taskbar Utility
    command: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    file: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    size: 188416
    MD5: 1D2F88932715651EEC76DDE73A981A93

    Located: HK_LM:Run, HPHmon05
    command: C:\WINDOWS\system32\hphmon05.exe
    file: C:\WINDOWS\system32\hphmon05.exe
    size: 483328
    MD5: EC273D5F06235F8F003316003F518EE3

    Located: HK_LM:Run, HPHUPD05
    command: C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    file: C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    size: 49152
    MD5: 671F926ABFABFB767D708BBEE49DF45D

    Located: HK_LM:Run, igfxhkcmd
    command: C:\WINDOWS\system32\hkcmd.exe
    file: C:\WINDOWS\system32\hkcmd.exe
    size: 77824
    MD5: 82ADC58B63E069AC4641A33EA9841E54

    Located: HK_LM:Run, igfxpers
    command: C:\WINDOWS\system32\igfxpers.exe
    file: C:\WINDOWS\system32\igfxpers.exe
    size: 114688
    MD5: A0E2FFB7B0FCE82AA3BCC3105306C45C

    Located: HK_LM:Run, igfxtray
    command: C:\WINDOWS\system32\igfxtray.exe
    file: C:\WINDOWS\system32\igfxtray.exe
    size: 94208
    MD5: 5656D65A9A9F1E3D68D64A350CFF1732

    Located: HK_LM:Run, iTunesHelper
    command: "C:\Program Files\iTunes\iTunesHelper.exe"
    file: C:\Program Files\iTunes\iTunesHelper.exe
    size: 141608
    MD5: E840A9AEA5D59A5E9C1C4F1AB24D197A

    Located: HK_LM:Run, QUICKCARE
    command: C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
    file: C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
    size: 192512
    MD5: 6E66CAFA1F8BE0E51B110B0E9B024702

    Located: HK_LM:Run, QuickTime Task
    command: "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    file: C:\Program Files\QuickTime\QTTask.exe
    size: 421888
    MD5: ED7A6D40B20DC34BE06F4AE196AE7D50

    Located: HK_LM:Run, SoundMAXPnP
    command: C:\Program Files\Analog Devices\Core\smax4pnp.exe
    file: C:\Program Files\Analog Devices\Core\smax4pnp.exe
    size: 1404928
    MD5: 10247C15D999CC116C87DA36BD0AD64D

    Located: HK_LM:Run, SunJavaUpdateSched
    command: "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    file: C:\Program Files\Common Files\Java\Java Update\jusched.exe
    size: 248040
    MD5: 52DB6CDAC5BC7A1FC884E97C41C91213

    Located: HK_CU:Run, ctfmon.exe
    where: S-1-5-21-540961431-1912937874-3570792479-1006...
    command: C:\WINDOWS\system32\ctfmon.exe
    file: C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3

    Located: HK_CU:Run, EPSON Stylus CX7400 Series
    where: S-1-5-21-540961431-1912937874-3570792479-1006...
    command: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S81D.tmp" /EF "HKCU"
    file: C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE
    size: 179200
    MD5: E9ACA584CE64C8296F5789BE8B6FE9F7

    Located: HK_CU:Run, SpybotSD TeaTimer
    where: S-1-5-21-540961431-1912937874-3570792479-1006...
    command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 2260480
    MD5: 390679F7A217A5E73D756276C40AE887

    Located: HK_CU:Run, WMPNSCFG
    where: S-1-5-21-540961431-1912937874-3570792479-1006...
    command: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    file: C:\Program Files\Windows Media Player\WMPNSCFG.exe
    size: 204288
    MD5: 7EAED08CCCA4DDDE61A388C82598CFA9

    Located: Startup (common), PictureMover.lnk
    where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup...
    command: C:\Program Files\PictureMover\Bin\PictureMover.exe
    file: C:\Program Files\PictureMover\Bin\PictureMover.exe
    size: 413696
    MD5: 5946348F9F4A467B2E78C0B71A4859DD

    Located: Startup (user), ERUNT AutoBackup.lnk
    where: C:\Documents and Settings\ron\Start Menu\Programs\Startup...
    command: C:\Program Files\ERUNT\AUTOBACK.EXE
    file: C:\Program Files\ERUNT\AUTOBACK.EXE
    size: 38912
    MD5: E00DE20F0F6BED5CD2160247DDC9443B

    Located: WinLogon, avgrsstarter
    command: avgrsstx.dll
    file: avgrsstx.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, crypt32chain
    command: crypt32.dll
    file: crypt32.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cryptnet
    command: cryptnet.dll
    file: cryptnet.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, cscdll
    command: cscdll.dll
    file: cscdll.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, dimsntfy
    command: %SystemRoot%\System32\dimsntfy.dll
    file: %SystemRoot%\System32\dimsntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, igfxcui
    command: igfxdev.dll
    file: igfxdev.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, ScCertProp
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, Schedule
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, sclgntfy
    command: sclgntfy.dll
    file: sclgntfy.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, SensLogn
    command: WlNotify.dll
    file: WlNotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, termsrv
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, WgaLogon
    command: WgaLogon.dll
    file: WgaLogon.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!

    Located: WinLogon, wlballoon
    command: wlnotify.dll
    file: wlnotify.dll
    size: 0
    MD5: D41D8CD98F00B204E9800998ECF8427E
    Warning: if the file is actually larger than 0 bytes,
    the checksum could not be properly calculated!



    --- Browser helper object list ---
    {18DF081C-E8AD-4283-A596-FA578C2EBDC3} (AcroIEHelperStub)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: AcroIEHelperStub
    CLSID name: Adobe PDF Link Helper
    Path: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\
    Long name: AcroIEHelperShim.dll
    Short name: ACROIE~2.DLL
    Date (created): 6/19/2010 2:29:34 PM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 6/19/2010 2:29:34 PM
    Filesize: 75200
    Attributes: archive
    MD5: 6D9042F1443A601DA8DC24D991EDDD0A
    CRC32: 10990AC8
    Version: 9.3.3.177

    {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} (WormRadar.com IESiteBlocker.NavFilter)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: WormRadar.com IESiteBlocker.NavFilter
    CLSID name: AVG Safe Search
    Path: C:\Program Files\AVG\AVG9\
    Long name: avgssie.dll
    Short name:
    Date (created): 7/15/2010 9:39:06 AM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 7/21/2010 8:27:12 AM
    Filesize: 1619296
    Attributes: archive
    MD5: 9709500432501607C7DD32B9F2B07E1F
    CRC32: DD3F49C2
    Version: 9.0.0.845

    {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Spybot-S&D IE Protection
    description: Spybot-S&D IE Browser plugin
    classification: Legitimate
    known filename: SDhelper.dll
    info link: http://spybot.eon.net.au/
    info source: Patrick M. Kolla
    Path: C:\Program Files\Spybot - Search & Destroy\
    Long name: SDHelper.dll
    Short name:
    Date (created): 6/12/2006 1:03:26 PM
    Date (last access): 8/30/2010 5:36:36 PM
    Date (last write): 1/26/2009 4:31:02 PM
    Filesize: 1879896
    Attributes: archive
    MD5: 022C2F6DCCDFA0AD73024D254E62AFAC
    CRC32: 5BA24007
    Version: 1.6.2.14

    {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: AOL Toolbar Launcher
    CLSID name: AOL Toolbar Launcher
    Path: C:\Program Files\AOL\AIM Toolbar 5.0\
    Long name: aoltb.dll
    Short name:
    Date (created): 10/10/2007 9:57:00 AM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 10/10/2007 9:57:00 AM
    Filesize: 1090912
    Attributes: archive
    MD5: D5553581358B506E1A6B76727B9A4451
    CRC32: 5AE3D053
    Version: 5.0.75.1

    {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name:

    {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Windows Live Sign-in Helper
    Path: C:\Program Files\Common Files\Microsoft Shared\Windows Live\
    Long name: WindowsLiveLogin.dll
    Short name: WINDOW~1.DLL
    Date (created): 8/31/2006 8:33:06 PM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 8/31/2006 8:33:06 PM
    Filesize: 322368
    Attributes: archive
    MD5: E43F7CFDEE2B00A22C96C168147B20D3
    CRC32: 2AEACC43
    Version: 4.100.313.1

    {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Google Toolbar Helper
    description: Google toolbar
    classification: Open for discussion
    known filename: googletoolbar.dll<br>googletoolbar*.dll<br>(* = number)<br>googletoolbar_en_*.**-big.dll<br>Googletoolbar_en_*.*.**-deleon.dll
    info link: http://toolbar.google.com/
    info source: TonyKlein
    Path: c:\program files\google\
    Long name: GoogleToolbar3.dll
    Short name: GOOGLE~3.DLL
    Date (created): 2/14/2007 6:45:14 PM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 1/20/2007 12:55:32 AM
    Filesize: 2403392
    Attributes: readonly archive
    MD5: 6319F2D4708DBCAE37CFA03DA10782C0
    CRC32: D51D8296
    Version: 4.0.1601.4978

    {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Google Toolbar Notifier BHO
    Path: C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\
    Long name: swg.dll
    Short name:
    Date (created): 10/12/2008 11:10:50 AM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 10/12/2008 11:10:50 AM
    Filesize: 737776
    Attributes: archive
    MD5: AB32387A8F8C696A0739768B6B913714
    CRC32: F4E76414
    Version: 3.1.807.1746

    {d2ce3e00-f94a-4740-988e-03dc2f38c34f} (MSN Toolbar Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: MSN Toolbar Helper
    Path: C:\Program Files\MSN\Toolbar\3.0.0988.2\
    Long name: msneshellx.dll
    Short name: MSNESH~1.DLL
    Date (created): 12/4/2008 1:29:32 PM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 12/4/2008 1:29:32 PM
    Filesize: 83800
    Attributes: archive
    MD5: 45C45845FD810BC6A205AE9AAB442FE9
    CRC32: EA2D87CA
    Version: 3.0.988.2

    {DBC80044-A445-435b-BC74-9C25C1C588A9} (Java(tm) Plug-In 2 SSV Helper)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name:
    CLSID name: Java(tm) Plug-In 2 SSV Helper
    Path: C:\Program Files\Java\jre6\bin\
    Long name: jp2ssv.dll
    Short name:
    Date (created): 5/23/2010 11:57:50 AM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 5/23/2010 11:57:50 AM
    Filesize: 41760
    Attributes: archive
    MD5: 385BD69743EA92E76CDF07B3345A25D5
    CRC32: D47CB5BA
    Version: 6.0.200.2

    {E7E6F031-17CE-4C07-BC86-EABFE594F69C} (JQSIEStartDetectorImpl)
    location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    BHO name: JQSIEStartDetectorImpl
    CLSID name: JQSIEStartDetectorImpl Class
    Path: C:\Program Files\Java\jre6\lib\deploy\jqs\ie\
    Long name: jqs_plugin.dll
    Short name: JQS_PL~1.DLL
    Date (created): 5/23/2010 11:57:52 AM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 5/23/2010 11:57:52 AM
    Filesize: 79648
    Attributes: archive
    MD5: 4E2BB6D2677B42AD04BE18A6E9817B68
    CRC32: 2F05ABD7
    Version: 6.0.200.2



    --- ActiveX list ---
    {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object)
    DPF name:
    CLSID name: QuickTime Object
    Installer: C:\WINDOWS\Downloaded Program Files\QTPlugin.inf
    Codebase: http://www.apple.com/qtactivex/qtplugin.cab
    description: Apple Quicktime
    classification: Legitimate
    known filename: QTPLUGIN.OCX
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\QuickTime\
    Long name: QTPlugin.ocx
    Short name:
    Date (created): 3/17/2010 11:28:24 PM
    Date (last access): 8/30/2010 5:36:46 PM
    Date (last write): 3/17/2010 11:28:24 PM
    Filesize: 800048
    Attributes: archive
    MD5: AD99EC8908185A02307CF071EF7BD9CF
    CRC32: D29F3B77
    Version: 7.6.6.0

    {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control)
    DPF name:
    CLSID name: Facebook Photo Uploader 5 Control
    Installer: C:\WINDOWS\Downloaded Program Files\PhotoUploader5.inf
    Codebase: http://upload.facebook.com/controls/...oUploader5.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: PhotoUploader5.ocx
    Short name: PHOTOU~1.OCX
    Date (created): 10/10/2008 4:44:58 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 10/10/2008 4:44:58 PM
    Filesize: 3536384
    Attributes: archive
    MD5: 3F703EC5DB5638C08008132A78430136
    CRC32: AB0E6745
    Version: 5.5.8.0

    {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control)
    DPF name:
    CLSID name: Shockwave ActiveX Control
    Installer: C:\WINDOWS\Downloaded Program Files\swdir.inf
    Codebase: http://fpdownload.macromedia.com/get...irector/sw.cab
    description: Macromedia ShockWave Flash Player 7
    classification: Legitimate
    known filename: SWDIR.DLL
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Adobe\Director\
    Long name: SwDir.dll

    {33564D57-0000-0010-8000-00AA00389B71} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\WMV9VCM.inf
    Codebase: http://download.microsoft.com/downlo...22/wmv9VCM.CAB
    description:
    classification: Legitimate
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia)
    DPF name:
    CLSID name: Snapfish Activia
    Installer: C:\WINDOWS\Downloaded Program Files\SnapfishActivia1000.inf
    Codebase: http://www2.snapfish.com/SnapfishActivia.cab
    description:
    classification: Legitimate
    known filename: SnapfishActivia1000.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: SnapfishActivia1000.ocx
    Short name: SNAPFI~1.OCX
    Date (created): 6/3/2005 12:24:32 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 6/3/2005 12:24:32 PM
    Filesize: 286720
    Attributes: archive
    MD5: F5C79C45F1ADF877DC3AFDFF3565AE7B
    CRC32: F118547A
    Version: 1.0.0.10

    {49232000-16E4-426C-A231-62846947304B} (SysData Class)
    DPF name:
    CLSID name: SysData Class
    Installer: C:\WINDOWS\Downloaded Program Files\sysinfo.inf
    Codebase: http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
    description:
    classification: Legitimate
    known filename: SysInfo.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\DOWNLO~1\
    Long name: SysInfo.dll
    Short name:
    Date (created): 5/15/2007 4:33:20 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 5/15/2007 4:33:20 PM
    Filesize: 251448
    Attributes: archive
    MD5: 55E8A05DDA26E8C455A7730721DCAF60
    CRC32: 38BB3B52
    Version: 2.4.0.0

    {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool)
    DPF name:
    CLSID name: MSN Photo Upload Tool
    Installer: C:\WINDOWS\Downloaded Program Files\MsnPUpld.inf
    Codebase: http://gfx2.mail.live.com/mail/w1/re...s/MSNPUpld.cab
    description:
    classification: Legitimate
    known filename: MsnPUpld.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: MsnPUpld.dll
    Short name:
    Date (created): 6/20/2006 3:44:04 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 6/20/2006 3:44:04 PM
    Filesize: 379704
    Attributes: archive
    MD5: D2FB109C3F0DAAAA4A73E5921656DB3E
    CRC32: A13093E8
    Version: 10.0.913.0

    {596AF4AC-40A0-474A-9F86-33F0A90F0FD6} (PictureItLauncher Class)
    DPF name:
    CLSID name: PictureItLauncher Class
    Installer: C:\WINDOWS\Downloaded Program Files\DigWebX2.inf
    Codebase: http://photos.msn.com/resources/neut...s/DigWebX2.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: DigWebX2.dll
    Short name:
    Date (created): 10/26/2004 4:23:18 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 10/26/2004 4:23:18 PM
    Filesize: 191488
    Attributes: archive
    MD5: 10C2882D1BFA2A2B92B691DCD39E96DA
    CRC32: 8715855C
    Version: 10.0.910.0

    {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control)
    DPF name:
    CLSID name: Facebook Photo Uploader 4 Control
    Installer: C:\WINDOWS\Downloaded Program Files\ImageUploader4.1.inf
    Codebase: http://upload.facebook.com/controls/...oUploader3.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: ImageUploader4.1.ocx
    Short name: IMAGEU~1.OCX
    Date (created): 11/26/2007 12:43:08 AM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 11/26/2007 12:43:08 AM
    Filesize: 2663944
    Attributes: archive
    MD5: DA18FD0966274164F4AC1797282BA479
    CRC32: 41EA81A4
    Version: 4.5.57.0

    {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control)
    DPF name:
    CLSID name: Facebook Photo Uploader Control
    Installer: C:\WINDOWS\Downloaded Program Files\FacebookPhotoUploader.inf
    Codebase: http://upload.facebook.com/controls/...toUploader.cab
    description:
    classification: Open for discussion
    known filename: FacebookPhotoUploader.ocx
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: FacebookPhotoUploader.ocx
    Short name: FACEBO~1.OCX
    Date (created): 11/3/2005 8:17:36 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 11/3/2005 8:17:36 PM
    Filesize: 1935120
    Attributes: archive
    MD5: 5A39F109CB87893FD683F49699BCE2B4
    CRC32: 729D4EBC
    Version: 3.5.122.2

    {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
    DPF name:
    CLSID name: WUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\wuweb.inf
    Codebase: http://update.microsoft.com/windowsu...?1150132468906
    description:
    classification: Legitimate
    known filename: wuweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: wuweb.dll
    Short name:
    Date (created): 8/11/2004 5:12:56 PM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 8/6/2009 7:24:18 PM
    Filesize: 209632
    Attributes: archive
    MD5: 033AF4CE25B6D871F0DE2C982658E049
    CRC32: 2C204902
    Version: 7.4.7600.226

    {6B75345B-AA36-438A-BBE6-4078B4C6984D} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\setup.inf
    Codebase: http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    description:
    classification: Legitimate
    known filename: HPDeviceDetection.dll
    info link:
    info source: Safer Networking Ltd.

    {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class)
    DPF name:
    CLSID name: MUWebControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\muweb.inf
    Codebase: http://update.microsoft.com/microsof...?1150132521938
    description:
    classification: Legitimate
    known filename: muweb.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\system32\
    Long name: muweb.dll
    Short name:
    Date (created): 5/26/2005 4:19:32 AM
    Date (last access): 8/30/2010 5:36:48 PM
    Date (last write): 8/6/2009 7:23:46 PM
    Filesize: 215920
    Attributes: archive
    MD5: A1350D646EF6E57E8F4F33EBE7320D08
    CRC32: AB3CA24F
    Version: 7.4.7600.226

    {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class)
    DPF name:
    CLSID name: Kodak Gallery Easy Upload Manager Class
    Installer: C:\WINDOWS\Downloaded Program Files\axofupld.inf
    Codebase: http://targetphoto.kodakgallery.com/...2/axofupld.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: axofupld.dll
    Short name:
    Date (created): 8/21/2007 12:30:00 PM
    Date (last access): 8/30/2010 5:36:50 PM
    Date (last write): 8/21/2007 12:30:00 PM
    Filesize: 196608
    Attributes: archive
    MD5: 6D7A5FA14CADB19AD77B20A054F8C14A
    CRC32: CCB39000
    Version: 2.2.1.25

    {7530BFB8-7293-4D34-9923-61A11451AFC5} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\OnlineScanner.inf
    Codebase: http://download.eset.com/special/eos/OnlineScanner.cab

    {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_20
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description: Sun Java
    classification: Legitimate
    known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
    info link:
    info source: Patrick M. Kolla
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_20.dll
    Short name: NPJPI1~1.DLL
    Date (created): 5/23/2010 11:57:50 AM
    Date (last access): 8/30/2010 5:36:50 PM
    Date (last write): 5/23/2010 11:57:50 AM
    Filesize: 136992
    Attributes: archive
    MD5: E06930C34F16C8AD24AD79502F40026A
    CRC32: 529E0B62
    Version: 6.0.200.2

    {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\erma.inf
    Codebase: http://fpdownload.macromedia.com/get.../ultrashim.cab
    description:
    classification: Open for discussion
    known filename:
    info link:
    info source: Safer Networking Ltd.

    {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin)
    DPF name:
    CLSID name: Shutterfly Picture Upload Plugin
    Installer: C:\WINDOWS\Downloaded Program Files\sfuploadplugin.inf
    Codebase: http://web1.shutterfly.com/downloads/Uploader.cab
    description:
    classification: Legitimate
    known filename: SFUPLO~1.OCX
    info link:
    info source: Safer Networking Ltd.
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: sfuploadplugin.ocx
    Short name: SFUPLO~1.OCX
    Date (created): 1/4/2007 11:43:24 AM
    Date (last access): 8/30/2010 5:36:50 PM
    Date (last write): 1/4/2007 11:43:24 AM
    Filesize: 1898216
    Attributes: archive
    MD5: 080FA21337AE2364B39A263E5AF7D326
    CRC32: E423146B
    Version: 2.0.4.0

    {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_20
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_20.dll
    Short name: NPJPI1~1.DLL
    Date (created): 5/23/2010 11:57:50 AM
    Date (last access): 8/30/2010 5:36:50 PM
    Date (last write): 5/23/2010 11:57:50 AM
    Filesize: 136992
    Attributes: archive
    MD5: E06930C34F16C8AD24AD79502F40026A
    CRC32: 529E0B62
    Version: 6.0.200.2

    {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0)
    DPF name: Java Runtime Environment 1.6.0
    CLSID name: Java Plug-in 1.6.0_20
    Installer:
    Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab
    description:
    classification: Legitimate
    known filename: npjpi150_06.dll
    info link:
    info source: Safer Networking Ltd.
    Path: C:\Program Files\Java\jre6\bin\
    Long name: npjpi160_20.dll
    Short name: NPJPI1~1.DLL
    Date (created): 5/23/2010 11:57:50 AM
    Date (last access): 8/30/2010 5:36:50 PM
    Date (last write): 5/23/2010 11:57:50 AM
    Filesize: 136992
    Attributes: archive
    MD5: E06930C34F16C8AD24AD79502F40026A
    CRC32: 529E0B62
    Version: 6.0.200.2

    {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
    DPF name:
    CLSID name: Shockwave Flash Object
    Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf
    Codebase: http://fpdownload.macromedia.com/pub...sh/swflash.cab
    description: Macromedia Shockwave Flash Player
    classification: Legitimate
    known filename:
    info link:
    info source: Patrick M. Kolla
    Path: C:\WINDOWS\system32\Macromed\Flash\
    Long name: Flash10e.ocx
    Short name:
    Date (created): 1/26/2010 7:58:36 PM
    Date (last access): 8/30/2010 5:36:52 PM
    Date (last write): 1/26/2010 7:58:36 PM
    Filesize: 3981080
    Attributes: readonly archive
    MD5: C06E6E160F34CE092301BD2B29067F3F
    CRC32: D922F8F5
    Version: 10.0.45.2

    {E2883E8F-472F-4FB0-9522-AC9BF37916A7} ()
    DPF name:
    CLSID name:
    Installer: C:\WINDOWS\Downloaded Program Files\gp.inf
    Codebase: http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

    {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class)
    DPF name:
    CLSID name: JuniperSetupClientControl Class
    Installer: C:\WINDOWS\Downloaded Program Files\JuniperSetupClient.INF
    Codebase: https://juniper.net/dana-cached/sc/J...etupClient.cab
    Path: C:\WINDOWS\Downloaded Program Files\
    Long name: JuniperSetupClient.ocx
    Short name: JUNIPE~1.OCX
    Date (created): 11/12/2009 9:13:30 PM
    Date (last access): 8/30/2010 5:36:52 PM
    Date (last write): 11/12/2009 9:13:30 PM
    Filesize: 230696
    Attributes: archive
    MD5: FD883FC2C02AA5B46937F34B86542A07
    CRC32: E753D7BD
    Version: 2.1.1.1



    --- Process list ---
    PID: 0 ( 0) [System]
    PID: 620 ( 4) \SystemRoot\System32\smss.exe
    size: 50688
    PID: 676 ( 620) \??\C:\WINDOWS\system32\csrss.exe
    size: 6144
    PID: 700 ( 620) \??\C:\WINDOWS\system32\winlogon.exe
    size: 507904
    PID: 744 ( 700) C:\WINDOWS\system32\services.exe
    size: 110592
    MD5: 65DF52F5B8B6E9BBD183505225C37315
    PID: 756 ( 700) C:\WINDOWS\system32\lsass.exe
    size: 13312
    MD5: BF2466B3E18E970D8A976FB95FC1CA85
    PID: 928 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 996 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1092 ( 744) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    size: 1778480
    MD5: C9C764ED6400D2F14D2652EF7F530005
    PID: 1120 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1220 ( 700) C:\Program Files\AVG\AVG9\avgchsvx.exe
    size: 1101152
    MD5: 031DD8DBD4B958B5765C8C111CB1EA03
    PID: 1228 ( 700) C:\Program Files\AVG\AVG9\avgrsx.exe
    size: 515424
    MD5: 5654DB4719A3C52684A20C1CA443BF8F
    PID: 1424 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1504 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1596 (1228) C:\Program Files\AVG\AVG9\avgcsrvx.exe
    size: 723296
    MD5: 78EF60FECB03144780151FD934BBAB94
    PID: 1744 ( 744) C:\WINDOWS\system32\spoolsv.exe
    size: 57856
    MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B
    PID: 1880 (1844) C:\WINDOWS\Explorer.EXE
    size: 1033728
    MD5: 12896823FB95BFB3DC9B46BCAEDC9923
    PID: 456 (1880) C:\Program Files\Analog Devices\Core\smax4pnp.exe
    size: 1404928
    MD5: 10247C15D999CC116C87DA36BD0AD64D
    PID: 472 (1880) C:\WINDOWS\system32\hkcmd.exe
    size: 77824
    MD5: 82ADC58B63E069AC4641A33EA9841E54
    PID: 480 (1880) C:\WINDOWS\system32\igfxpers.exe
    size: 114688
    MD5: A0E2FFB7B0FCE82AA3BCC3105306C45C
    PID: 492 (1880) C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
    size: 192512
    MD5: 6E66CAFA1F8BE0E51B110B0E9B024702
    PID: 544 (1880) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    size: 221184
    MD5: C130EAE1DA69AC31208880EF5E0BEC4C
    PID: 568 (1880) C:\WINDOWS\system32\hphmon05.exe
    size: 483328
    MD5: EC273D5F06235F8F003316003F518EE3
    PID: 652 (1880) C:\Program Files\AVG\AVG9\avgtray.exe
    size: 2065760
    MD5: E9B04FD2921ACE22CA17FA7D5131F491
    PID: 804 (1880) C:\Program Files\Common Files\Java\Java Update\jusched.exe
    size: 248040
    MD5: 52DB6CDAC5BC7A1FC884E97C41C91213
    PID: 1340 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 1664 (1880) C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    size: 2039240
    MD5: E25076570C6CC864043047325AF16F44
    PID: 1804 (1880) C:\Program Files\iTunes\iTunesHelper.exe
    size: 141608
    MD5: E840A9AEA5D59A5E9C1C4F1AB24D197A
    PID: 1688 (1880) C:\WINDOWS\system32\ctfmon.exe
    size: 15360
    MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3
    PID: 2020 ( 744) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    size: 144176
    MD5: 2E3E53A6AEF23E24F402C7855B9B1542
    PID: 2068 (1880) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    size: 2260480
    MD5: 390679F7A217A5E73D756276C40AE887
    PID: 2072 ( 744) C:\Program Files\AVG\AVG9\avgwdsvc.exe
    size: 308136
    MD5: C4D15594DB5BE042D3346EA58DF87D89
    PID: 2128 ( 744) C:\Program Files\Bonjour\mDNSResponder.exe
    size: 345376
    MD5: 5AB58C337AC65837FE404462AD6265AB
    PID: 2144 (1880) C:\Program Files\Windows Media Player\WMPNSCFG.exe
    size: 204288
    MD5: 7EAED08CCCA4DDDE61A388C82598CFA9
    PID: 2272 ( 744) C:\WINDOWS\System32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 2452 (1880) C:\Program Files\PictureMover\Bin\PictureMover.exe
    size: 413696
    MD5: 5946348F9F4A467B2E78C0B71A4859DD
    PID: 2472 ( 744) C:\Program Files\Java\jre6\bin\jqs.exe
    size: 153376
    MD5: 1834C96FB1F9280BCF6DDFA6DE8338BF
    PID: 2972 ( 744) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    size: 322120
    MD5: 11F714F85530A2BD134074DC30E99FCA
    PID: 3156 ( 744) C:\WINDOWS\system32\HPZipm12.exe
    size: 69632
    MD5: 9D84376931440F3679BEEF2A414FA493
    PID: 3328 ( 744) C:\WINDOWS\system32\svchost.exe
    size: 14336
    MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18
    PID: 3476 ( 744) C:\Program Files\Viewpoint\Common\ViewpointService.exe
    size: 24652
    MD5: 5F974FDE801C73952770736BECDE11E7
    PID: 3548 (2072) C:\Program Files\AVG\AVG9\avgnsx.exe
    size: 620896
    MD5: 7C8E0F172E0BE4F9A25E766F84D22E64
    PID: 3836 ( 744) C:\Program Files\Windows Media Player\WMPNetwk.exe
    size: 913408
    MD5: F74E3D9A7FA9556C3BBB14D4E5E63D3B
    PID: 1168 ( 744) C:\Program Files\iPod\bin\iPodService.exe
    size: 540968
    MD5: F92048E22CB392BBC3C38EF393C0E4A6
    PID: 528 ( 744) C:\WINDOWS\System32\alg.exe
    size: 44544
    MD5: 8C515081584A38AA007909CD02020B3D
    PID: 3952 ( 804) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
    size: 490728
    MD5: D4DDB8CF58103E8CE8E99101C467C979
    PID: 3256 (1880) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    size: 5365592
    MD5: 0477C2F9171599CA5BC3307FDFBA8D89
    PID: 3228 (3052) C:\Documents and Settings\ron\Application Data\Juniper Networks\Setup Client\JuniperSetupClient.exe
    size: 496936
    MD5: D5C992CA0BF6DBA2B1096299237049D3
    PID: 680 (1880) C:\Program Files\Mozilla Firefox\firefox.exe
    size: 910296
    MD5: BACCDA841C689D1CBA941F478E8ED24B
    PID: 3436 ( 680) C:\Program Files\Mozilla Firefox\plugin-container.exe
    size: 14808
    MD5: 642FA80C2C43EE609313746AA305DC86
    PID: 3112 (1880) C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
    size: 10354000
    MD5: 41D5501224ADAE9BBC7AF91AF2615613
    PID: 4 ( 0) System


    --- Browser start & search pages list ---
    Spybot - Search & Destroy browser pages report, 8/30/2010 6:24:36 PM

    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
    http://www.microsoft.com/isapi/redir...ie&ar=iesearch
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
    http://www.msn.com/
    HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
    http://www.google.com/keyword/%s
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
    C:\WINDOWS\system32\blank.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
    http://go.microsoft.com/fwlink/?LinkId=69157
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
    http://go.microsoft.com/fwlink/?LinkId=54896
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
    HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
    http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


    --- Winsock Layered Service Provider list ---
    Protocol 0: MSAFD Tcpip [TCP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 1: MSAFD Tcpip [UDP/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 2: MSAFD Tcpip [RAW/IP]
    GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP IP protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD Tcpip[*]

    Protocol 3: RSVP UDP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 4: RSVP TCP Service Provider
    GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
    Filename: %SystemRoot%\system32\rsvpsp.dll
    Description: Microsoft Windows NT/2k/XP RVSP
    DB filename: %SystemRoot%\system32\rsvpsp.dll
    DB protocol: RSVP * Service Provider

    Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{37A0395D-CE3C-43B4-904B-C3ED107A7DCF}] SEQPACKET 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{37A0395D-CE3C-43B4-904B-C3ED107A7DCF}] DATAGRAM 0
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EA219350-B25F-4304-B0A7-CA6C15D25C3F}] SEQPACKET 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{EA219350-B25F-4304-B0A7-CA6C15D25C3F}] DATAGRAM 1
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C8FB8631-14EB-4BD0-9EBA-74664FE3AF1E}] SEQPACKET 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C8FB8631-14EB-4BD0-9EBA-74664FE3AF1E}] DATAGRAM 2
    GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
    Filename: %SystemRoot%\system32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP NetBios protocol
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: MSAFD NetBIOS *

    Namespace Provider 0: Tcpip
    GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: TCP/IP

    Namespace Provider 1: NTDS
    GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
    Filename: %SystemRoot%\System32\winrnr.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\winrnr.dll
    DB protocol: NTDS

    Namespace Provider 2: Network Location Awareness (NLA) Namespace
    GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
    Filename: %SystemRoot%\System32\mswsock.dll
    Description: Microsoft Windows NT/2k/XP name space provider
    DB filename: %SystemRoot%\system32\mswsock.dll
    DB protocol: NLA-Namespace

    Namespace Provider 3: mdnsNSP
    GUID: {B600E6E9-553B-4A19-8696-335E5C896153}
    Filename: C:\Program Files\Bonjour\mdnsNSP.dll
    Description: Apple Rendezvous protocol
    DB filename: %ProgramFiles%\Rendezvous\bin\mdnsNSP.dll
    DB protocol: mdnsNSP

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Ok, that might be a false positive.

    Please go to Kaspersky website and perform an online antivirus scan.

    1. Read through the requirements and privacy statement and click on Accept button.
    2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
    3. When the downloads have finished, click on Settings.
    4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      • Spyware, Adware, Dialers, and other potentially dangerous programs
        Archives
    5. Click on My Computer under Scan.
    6. Once the scan is complete, it will display the results. Click on View Scan Report.
    7. You will see a list of infected items there. Click on Save Report As....
    8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
    9. Please post this log in your next reply along with a fresh HijackThis log.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Member
    Join Date
    Feb 2009
    Posts
    37

    Default

    Here's the Kaspersky scan report:

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Thursday, September 2, 2010
    Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Wednesday, September 01, 2010 15:43:03
    Records in database: 4173897
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    A:\
    C:\
    D:\
    F:\
    G:\
    H:\

    Scan statistics:
    Objects scanned: 112704
    Threats found: 1
    Infected objects found: 1
    Suspicious objects found: 0
    Scan duration: 03:18:33


    File name / Threat / Threats count
    C:\Program Files\AIM6\addressBook.exe Infected: Trojan.Win32.Vilsel.ajgl 1

    Selected area has been scanned.

    Here's the HijackThis log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 6:59:39 AM, on 9/2/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\AVG\AVG9\avgchsvx.exe
    C:\Program Files\AVG\AVG9\avgrsx.exe
    C:\Program Files\AVG\AVG9\avgcsrvx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\hphmon05.exe
    C:\PROGRA~1\AVG\AVG9\avgtray.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\AVG\AVG9\avgwdsvc.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Windows Media Player\WMPNSCFG.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\PictureMover\Bin\PictureMover.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Viewpoint\Common\ViewpointService.exe
    C:\Program Files\AVG\AVG9\avgnsx.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Common Files\Java\Java Update\jucheck.exe
    C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
    C:\Documents and Settings\ron\Application Data\Juniper Networks\Setup Client\JuniperSetupClient.exe
    C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Program Files\AVG\AVG9\avgui.exe
    C:\Program Files\Java\jre6\bin\java.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O3 - Toolbar: AIM Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
    O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [EPSON Stylus CX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDA.EXE /FU "C:\WINDOWS\TEMP\E_S81D.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: PictureMover.lnk = C:\Program Files\PictureMover\Bin\PictureMover.exe
    O9 - Extra button: AIM Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AIM Toolbar 5.0\aoltb.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/...oUploader5.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqna/downloads/sysinfo.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/re...s/MSNPUpld.cab
    O16 - DPF: {596AF4AC-40A0-474A-9F86-33F0A90F0FD6} (PictureItLauncher Class) - http://photos.msn.com/resources/neut...s/DigWebX2.cab
    O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/...oUploader3.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1150132468906
    O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} - http://h20270.www2.hp.com/ediags/gmn...tDetection.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1150132521938
    O16 - DPF: {6F750202-1362-4815-A476-88533DE61D0C} (Kodak Gallery Easy Upload Manager Class) - http://targetphoto.kodakgallery.com/...2/axofupld.cab
    O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
    O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} (JuniperSetupClientControl Class) - https://juniper.net/dana-cached/sc/J...etupClient.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
    O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
    O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    --
    End of file - 11118 bytes

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please click this link-->Jotti

    Copy/paste file on the list into the white Upload a file box and click Submit/Send (depends on which one you are using Jotti or VirusTotal).

    C:\Program Files\AIM6\addressBook.exe

    Please post back the results of the scan in your next post.

    If Jotti is busy, try the same at Virustotal: http://www.virustotal.com/
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Member
    Join Date
    Feb 2009
    Posts
    37

    Default

    I'm not sure what results from the scan you need, but here is the information displayed on the page

    Filename: a.x
    Status:
    Scan finished. 4 out of 19 scanners reported malware.
    Scan taken on: Fri 13 Aug 2010 10:55:50 (CET) Permalink

    File size: 50736 bytes
    Filetype: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
    MD5: 057933071adff94757620e0ab8e6ead5
    SHA1: 9da939a3a9879bed487d9063820205d5177afc10

    [ArcaVir] 2010-08-13 Generic.20.118
    [G DATA] 2010-08-13 Found nothing
    [Avast! antivirus] 2010-08-12 Found nothing
    [Ikarus] 2010-08-13 Found nothing
    [Grisoft AVG Anti-Virus] 2010-08-12 Found nothing
    [Kaspersky Anti-Virus] 2010-08-13 Trojan.Win32.Vilsel.ajgl
    [Avira AntiVir] 2010-08-13 Found nothing
    [ESET NOD32] 2010-08-13 Found nothing
    [Softwin BitDefender] 2010-08-13 Found nothing
    [Panda Antivirus] 2010-08-12 Found nothing
    [ClamAV] 2010-08-13 Found nothing
    [Quick Heal] 2010-08-13 Found nothing
    [CPsecure] 2010-08-13 Found nothing
    [Sophos] 2010-08-13 Found nothing
    [Dr.Web] 2010-08-13 Found nothing
    [VirusBlokAda VBA32] 2010-08-11 Trojan.Win32.Vilsel.ajgl
    [Frisk F-Prot Antivirus] 2010-08-12 Found nothing
    [VirusBuster] 2010-08-12 Trojan.Vilsel.ILK
    [F-Secure Anti-Virus] 2010-08-13 Found nothing

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Do you recognize that file?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Member
    Join Date
    Feb 2009
    Posts
    37

    Default

    I'm not exactly sure which file you mean --

    C:\Program Files\AIM6\addressBook.exe

    or

    Filename: a.x

    I guess I don't really recognize either. I know that we have AOL instant messenger 6, and I assume that the address book holds the contacts. I don't really use it much though.

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please then rescan that file to see if it has been false positive and possibly fixed.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •