Gandle
2007-08-26, 10:33
F-Secure Log:
Scanning Report
Saturday, August 25, 2007 16:28:40 - 02:25:57
Computer name: YOUR-B689B7AA07
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\ E:\ F:\
--------------------------------------------------------------------------------
Result: 78 malware found
Tracking Cookie (spyware)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
Trojan-Downloader.Win32.Delf.pa (virus)
E:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\2BE05F09.DLL (Renamed & Submitted)
Vundo.gen38 (virus)
C:\WINDOWS\SYSTEM32\AXOHFBIN.INI (Submitted)
C:\WINDOWS\SYSTEM32\NJJQUADP.INI (Submitted)
C:\WINDOWS\SYSTEM32\NWIRURWR.INI (Submitted)
C:\WINDOWS\SYSTEM32\QQPXOWHQ.INI (Submitted)
W32/IRC_Flood.G (virus)
E:\PROGRAM FILES\MIRC\INVISION\STDIO.DLL (Submitted)
W32/Smalldoor.HBW (virus)
E:\DOWNLOADS\KILLBOX.EXE (Submitted)
W32/Vundo.dam (virus)
C:\WINDOWS\SYSTEM32\BJCUXDSI.DLL (Submitted)
C:\WINDOWS\SYSTEM32\BXVYHLTM.DLL (Submitted)
C:\WINDOWS\SYSTEM32\CBGNCOCY.DLL (Submitted)
C:\WINDOWS\SYSTEM32\EFPVKWUY.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NEGKNXWS.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NIBFHOXA.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NLTRESOE.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NNLMN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\PDAUQJJN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\QHWOXPQQ.DLL (Submitted)
C:\WINDOWS\SYSTEM32\QIJLVKBP.DLL (Submitted)
C:\WINDOWS\SYSTEM32\RKBDVMNI.DLL (Submitted)
C:\WINDOWS\SYSTEM32\RWRURIWN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\WFFHHSYE.DLL (Submitted)
Win32.TrojanDownloader.Agent (spyware)
System (Disinfected)
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 91628
System: 5183
Not scanned: 25
Actions:
Disinfected: 57
Renamed: 1
Deleted: 0
None: 20
Submitted: 21
Files not scanned:
C:\HIBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{514752F6-6816-435F-879D-2A19512E4E48}.BIN
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.4\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.3\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.2\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\USDR6_0001_D19M2108NETINSTALLER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\JAVA\JRE1.5.0_09\BIN\JUSCHED.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\DIGITAL MEDIA READER\SHWICONEM.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DW\DWTRIG20.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\BIGFIX\__DATA\EMACHINES\__LOCAL\MASTHEAD
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\BIGFIX\__DATA\BIGFIX\__LOCAL\MASTHEAD
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\DOCUMENTS AND SETTINGS\OWNER\MY DOCUMENTS\??CROSOFT\WINLOGON.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\WINDOWS\P_981116.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\QUICKTIME\QTTASK.EXE
D:\EXCURSION9.5\WEBVIEW\NHTMLN_2.92.DLL
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-08-24
F-Secure AVP: 7.0.171, 2007-08-24
F-Secure Orion: 1.2.37, 2007-08-24
F-Secure Blacklight: 1.0.64
F-Secure Draco: 1.0.35, 0597-150-72
F-Secure Pegasus: 1.19.0, 2007-07-19
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2006 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
Hijackthis Log:
Logfile of HijackThis v1.99.1
Scan saved at 2:32:59 AM, on 8/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.capella.edu/portal/login/loginuser.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [MSOffice] rundll32.exe "C:\WINDOWS\system32\cbgncocy.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O15 - Trusted Zone: http://vle1.capella.edu
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/luncher/GamesCampus.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1805/SkillGround.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n031p/EN/install/gtdownlr.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.8.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - http://download.games.yahoo.com/games/web_games/sony/davinci/DVCDownloadControl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\RpcSandraSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Scanning Report
Saturday, August 25, 2007 16:28:40 - 02:25:57
Computer name: YOUR-B689B7AA07
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\ E:\ F:\
--------------------------------------------------------------------------------
Result: 78 malware found
Tracking Cookie (spyware)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
System (Disinfected)
Trojan-Downloader.Win32.Delf.pa (virus)
E:\PROGRAM FILES\NORTON ANTIVIRUS\QUARANTINE\2BE05F09.DLL (Renamed & Submitted)
Vundo.gen38 (virus)
C:\WINDOWS\SYSTEM32\AXOHFBIN.INI (Submitted)
C:\WINDOWS\SYSTEM32\NJJQUADP.INI (Submitted)
C:\WINDOWS\SYSTEM32\NWIRURWR.INI (Submitted)
C:\WINDOWS\SYSTEM32\QQPXOWHQ.INI (Submitted)
W32/IRC_Flood.G (virus)
E:\PROGRAM FILES\MIRC\INVISION\STDIO.DLL (Submitted)
W32/Smalldoor.HBW (virus)
E:\DOWNLOADS\KILLBOX.EXE (Submitted)
W32/Vundo.dam (virus)
C:\WINDOWS\SYSTEM32\BJCUXDSI.DLL (Submitted)
C:\WINDOWS\SYSTEM32\BXVYHLTM.DLL (Submitted)
C:\WINDOWS\SYSTEM32\CBGNCOCY.DLL (Submitted)
C:\WINDOWS\SYSTEM32\EFPVKWUY.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NEGKNXWS.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NIBFHOXA.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NLTRESOE.DLL (Submitted)
C:\WINDOWS\SYSTEM32\NNLMN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\PDAUQJJN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\QHWOXPQQ.DLL (Submitted)
C:\WINDOWS\SYSTEM32\QIJLVKBP.DLL (Submitted)
C:\WINDOWS\SYSTEM32\RKBDVMNI.DLL (Submitted)
C:\WINDOWS\SYSTEM32\RWRURIWN.DLL (Submitted)
C:\WINDOWS\SYSTEM32\WFFHHSYE.DLL (Submitted)
Win32.TrojanDownloader.Agent (spyware)
System (Disinfected)
--------------------------------------------------------------------------------
Statistics
Scanned:
Files: 91628
System: 5183
Not scanned: 25
Actions:
Disinfected: 57
Renamed: 1
Deleted: 0
None: 20
Submitted: 21
Files not scanned:
C:\HIBERFIL.SYS
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\WINDOWS\SYSTEM32\CATROOT2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\CATDB
C:\WINDOWS\SYSTEM32\CATROOT2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\CATDB
C:\WINDOWS\SOFTWAREDISTRIBUTION\EVENTCACHE\{514752F6-6816-435F-879D-2A19512E4E48}.BIN
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.4\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.3\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.2\UWA7P_0001_N91M0809NETINSTALLER.EXE
C:\WINDOWS\DOWNLOADED PROGRAM FILES\CONFLICT.1\USDR6_0001_D19M2108NETINSTALLER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\JAVA\JRE1.5.0_09\BIN\JUSCHED.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\DIGITAL MEDIA READER\SHWICONEM.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\CYBERLINK\POWERDVD\PDVDSERV.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\YAZZLE1122OINUNINSTALLER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\DW\DWTRIG20.EXE
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\BIGFIX\__DATA\EMACHINES\__LOCAL\MASTHEAD
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\BIGFIX\__DATA\BIGFIX\__LOCAL\MASTHEAD
C:\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\ADOBE\ACROBAT 7.0\READER\ADOBEUPDATEMANAGER.EXE
C:\MY BACKUP -- 07-02-11 0842PM\DOCUMENTS AND SETTINGS\OWNER\MY DOCUMENTS\??CROSOFT\WINLOGON.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\WINDOWS\P_981116.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\WINAMP\WINAMPA.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\SYMANTEC ANTIVIRUS\VPTRAY.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\DESKTOP\MY BACKUP -- 07-02-11 0842PM\MY BACKUP -- 07-02-11 0842PM\PROGRAM FILES\QUICKTIME\QTTASK.EXE
D:\EXCURSION9.5\WEBVIEW\NHTMLN_2.92.DLL
--------------------------------------------------------------------------------
Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-08-24
F-Secure AVP: 7.0.171, 2007-08-24
F-Secure Orion: 1.2.37, 2007-08-24
F-Secure Blacklight: 1.0.64
F-Secure Draco: 1.0.35, 0597-150-72
F-Secure Pegasus: 1.19.0, 2007-07-19
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB BAT LNK ANI AVB CEO CMD LSP MAP MHT MIF PDF PHP POT WMF NWS TAR TGZ WSF ZL? {* ZIP JAR ARJ LZH TAR TGZ GZ CAB RAR BZ2 HQX
Use Advanced heuristics
--------------------------------------------------------------------------------
Copyright © 1998-2006 Product support |Send virus sample to F-Secure
F-Secure assumes no responsibility for material created or published by third parties that F-Secure World Wide Web pages have a link to. Unless you have clearly stated otherwise, by submitting material to any of our servers, for example by E-mail or via our F-Secure's CGI E-mail, you agree that the material you make available may be published in the F-Secure World Wide Pages or hard-copy publications. You will reach F-Secure public web site by clicking on underlined links. While doing this, your access will be logged to our private access statistics with your domain name.This information will not be given to any third party. You agree not to take action against us in relation to material that you submit. Unless you have clearly stated otherwise, by submitting material you warrant that F-Secure may incorporate any concepts described in it in the F-Secure products/publications without liability.
Hijackthis Log:
Logfile of HijackThis v1.99.1
Scan saved at 2:32:59 AM, on 8/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fsgk32.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\OnlineScanner\Anti-Virus\fssm32.exe
C:\Documents and Settings\Owner\My Documents\Downloads\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.capella.edu/portal/login/loginuser.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [MSOffice] rundll32.exe "C:\WINDOWS\system32\cbgncocy.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: ymetray.lnk = C:\Program Files\Yahoo!\Yahoo! Music Jukebox\ymetray.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O15 - Trusted Zone: http://vle1.capella.edu
O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/luncher/GamesCampus.cab
O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {0F733F27-5BBB-4D03-8D6B-19E2143880BF} (SkillGround Game Manager) - http://www1.skillground.com/cab1805/SkillGround.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n031p/EN/install/gtdownlr.cab
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.0.8.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
O16 - DPF: {ABB660B6-6694-407B-950A-EDBA5A159722} (DVCDownloadControl) - http://download.games.yahoo.com/games/web_games/sony/davinci/DVCDownloadControl.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_games/popcap/bejeweled2/popcaploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XI.SP1\RpcSandraSrv.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe