rage4
2006-03-14, 10:11
Hi I need help removing malicious files, I have been hit with all at once, from my computer. It fist started as an illegal operation running in dos. I got a error message sayin various .tmp files could not execute (or somethin like that). As far as I can tell either TrojanDownloader.Win32.Zlob.ci (yahoo anti-spy) LOCATION C:\WINDOWS\system32\winzal32.dll or
Trojan.Zlob (running process mssearchnet.exe) as pointed out by Norton in file C:\WINDOWS\system32\1024\ldc726.tmp and various .tmp, downloaded other threats on my computer.
I've also tried uninstalling spyfalcon but it keeps coming back. I am also recieving other messages saying Im infected (when I click on the newest one it takes me to Pesttrap). On top of all that I keep getting IE pop-up sayin im infected that lead to various spyware removal tools (bogus).
I have ran spybot and "removed" some threats but they keep coming back. I read the forum on removing the spyaxe family but In all this calamity I recieved a ballon pop-up from my tool bar saying I have iworm_attck_v122.02a, which norton doesnt pick up, so I wasnt sure if it would take care of that. Im pretty good with computers but this one got me intregued. What is the cause of all this, smitfraud, W32.Sinnaka.A@mm? How does it work behind my back.
I was also considering uninstalling Norton and installing Symantec Anti-Virus given to me for free from my school. What do you recommend. Also I heard Adaware attracts spyware is this true. I have used it before and found it very useful.
Here is my Hijackthis and Norton logfiles.
Thanks. Your help is greatly appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 12:46:06 AM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\arae\tsad.exe
C:\Documents and Settings\Administrator\Application Data\s?stem32\l?gonui.exe
C:\Program Files\Webshots\webshots.scr
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\win14E6.tmp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Administrator\My Documents\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R3 - URLSearchHook: (no name) - {C6AE2461-C8F7-BF5A-A4AC-EDCB259F59B7} - C:\WINDOWS\system32\hnzkxh.dll (file missing)
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBA91.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Arma] "C:\Program Files\arae\tsad.exe" -vt yax
O4 - HKCU\..\Run: [Porlb] C:\Documents and Settings\Administrator\Application Data\s?stem32\l?gonui.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - file://C:\Program Files\Gateway\helpspot\TechTools.CAB
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - file://C:\Program Files\Gateway\helpspot\RunExeActiveX.CAB
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - file://C:\Program Files\Gateway\helpspot\StartFirstControl.CAB
O16 - DPF: {CE37E095-ACFF-4380-A856-A560D389E5E1} (XPLControlProject.XPLControl) - file://C:\Program Files\Gateway\helpspot\XPLControl.CAB
O20 - Winlogon Notify: winxru32 - C:\WINDOWS\SYSTEM32\winxru32.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Category: Virus alerts
Date,Feature,Virus Name,Action Taken,Item Type,Target,Suspicious Action,User Name,Computer Name,Details
3/13/2006 11:58:47 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldA701.tmp
3/13/2006 11:33:45 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldBAF5.tmp
3/11/2006 8:02:41 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld68B5.tmp
3/9/2006 12:46:01 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:03 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:03 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:28 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:28 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:17 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:17 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:29:24 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld5C39.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:04:23 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld765C.tmp
3/9/2006 2:39:19 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld84B8.tmp
3/9/2006 2:14:19 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld9F84.tmp
3/9/2006 1:49:18 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldB974.tmp
3/9/2006 1:24:20 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldC726.tmp
3/9/2006 12:59:46 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld7BD9.tmp
3/9/2006 12:33:37 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldB96E.tmp
3/9/2006 12:08:05 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld3427.tmp
Trojan.Zlob (running process mssearchnet.exe) as pointed out by Norton in file C:\WINDOWS\system32\1024\ldc726.tmp and various .tmp, downloaded other threats on my computer.
I've also tried uninstalling spyfalcon but it keeps coming back. I am also recieving other messages saying Im infected (when I click on the newest one it takes me to Pesttrap). On top of all that I keep getting IE pop-up sayin im infected that lead to various spyware removal tools (bogus).
I have ran spybot and "removed" some threats but they keep coming back. I read the forum on removing the spyaxe family but In all this calamity I recieved a ballon pop-up from my tool bar saying I have iworm_attck_v122.02a, which norton doesnt pick up, so I wasnt sure if it would take care of that. Im pretty good with computers but this one got me intregued. What is the cause of all this, smitfraud, W32.Sinnaka.A@mm? How does it work behind my back.
I was also considering uninstalling Norton and installing Symantec Anti-Virus given to me for free from my school. What do you recommend. Also I heard Adaware attracts spyware is this true. I have used it before and found it very useful.
Here is my Hijackthis and Norton logfiles.
Thanks. Your help is greatly appreciated.
Logfile of HijackThis v1.99.1
Scan saved at 12:46:06 AM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\GWMDMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\Program Files\SpyFalcon\SpyFalcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\arae\tsad.exe
C:\Documents and Settings\Administrator\Application Data\s?stem32\l?gonui.exe
C:\Program Files\Webshots\webshots.scr
C:\WINDOWS\system32\nvctrl.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\TEMP\win14E6.tmp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Administrator\My Documents\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gatewaybiz.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gatewaybiz.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.gatewaybiz.com/
R3 - URLSearchHook: (no name) - {C6AE2461-C8F7-BF5A-A4AC-EDCB259F59B7} - C:\WINDOWS\system32\hnzkxh.dll (file missing)
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hpBA91.tmp
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [GWMDMMSG] GWMDMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SpyFalcon] C:\Program Files\SpyFalcon\SpyFalcon.exe /h
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Arma] "C:\Program Files\arae\tsad.exe" -vt yax
O4 - HKCU\..\Run: [Porlb] C:\Documents and Settings\Administrator\Application Data\s?stem32\l?gonui.exe
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {511073AD-BE56-4D43-AE68-93390514385E} (TechToolsActivex.TechTools) - file://C:\Program Files\Gateway\helpspot\TechTools.CAB
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - file://C:\Program Files\Gateway\helpspot\RunExeActiveX.CAB
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - file://C:\Program Files\Gateway\helpspot\StartFirstControl.CAB
O16 - DPF: {CE37E095-ACFF-4380-A856-A560D389E5E1} (XPLControlProject.XPLControl) - file://C:\Program Files\Gateway\helpspot\XPLControl.CAB
O20 - Winlogon Notify: winxru32 - C:\WINDOWS\SYSTEM32\winxru32.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Category: Virus alerts
Date,Feature,Virus Name,Action Taken,Item Type,Target,Suspicious Action,User Name,Computer Name,Details
3/13/2006 11:58:47 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldA701.tmp
3/13/2006 11:33:45 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldBAF5.tmp
3/11/2006 8:02:41 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld68B5.tmp
3/9/2006 12:46:01 PM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:19 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:42:18 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:04 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:03 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:38:03 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:29 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:28 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:28 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:17 AM,Auto-Protect,Download.Trojan,Access denied,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:37:17 AM,Auto-Protect,Download.Trojan,Repair failed,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\winzal32.dll
3/9/2006 3:29:24 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld5C39.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\SYSTEM32\HPEE01.TMP
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Repair failed,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:19:43 AM,Auto-Protect,Trojan.Zlob,Access denied,File,N/A,N/A,Administrator,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\hpEE01.tmp
3/9/2006 3:04:23 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld765C.tmp
3/9/2006 2:39:19 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld84B8.tmp
3/9/2006 2:14:19 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld9F84.tmp
3/9/2006 1:49:18 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldB974.tmp
3/9/2006 1:24:20 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldC726.tmp
3/9/2006 12:59:46 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld7BD9.tmp
3/9/2006 12:33:37 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ldB96E.tmp
3/9/2006 12:08:05 AM,Auto-Protect,Trojan.Zlob,Automatically deleted,File,N/A,N/A,SYSTEM,GATEWAY-F38F66E,Source: C:\WINDOWS\system32\1024\ld3427.tmp