PDA

View Full Version : Troubles



mcmill3
2006-06-20, 04:07
I downloaded a file in zip format and then all hell broke loose. I did a system restore from late last month with no change in system performance. Tons of popups, redirects, etc...

Hijack this log below. Any ideas from the below info?

Logfile of HijackThis v1.99.1
Scan saved at 9:04:20 PM, on 6/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\sysservice.exe
C:\dfndr.exe
C:\WINDOWS\SYSC00.exe
C:\PROGRA~1\COMMON~1\MANTEC~1\winspool.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\COMMON~1\FNTS~1\winspool.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
c:\windows\system32\dwdsregt.exe
C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\bin\HPOVDX05.EXE
C:\WINDOWS\system32\hpoipm07.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe

R3 - Default URLSearchHook is missing
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Microsoft Startup Manager] C:\WINDOWS\system32\sysservice.exe
O4 - HKLM\..\Run: [winlog] winlog.exe
O4 - HKLM\..\Run: [defender] C:\\dfndr.exe
O4 - HKLM\..\Run: [{AB-BA-A7-72-ZN}] c:\windows\system32\dwdsregt.exe GID003
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\RunServices: [winlog] winlog.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe"
O4 - HKCU\..\Run: [Shht] "C:\PROGRA~1\COMMON~1\MANTEC~1\winspool.exe" -vt yazr
O4 - HKCU\..\Run: [Mgcat] C:\PROGRA~1\COMMON~1\FNTS~1\winspool.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\pmdsregq.exe
O4 - Global Startup: HP OfficeJet T Series Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet T Series\Bin\HPOstr05.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &MyToolBar Search - res://C:\Program Files\ToolBar888\MyToolBar.dll/MENUSEARCH.HTM
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O20 - AppInit_DLLs: C:\WINDOWS\system32\wowexec.dll
O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\
O20 - Winlogon Notify: xcdmfree - xcdmfree.dll (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Unknown owner - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe (file missing)
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

mcmill3
2006-06-20, 04:11
Report from SpyBot below, may help.

Command Service: System Service (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService

CAS-Client: Executable (File, fixed)
C:\WINDOWS\flntzcm.exe_tobedeleted

Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService\\SYSTEM\CurrentControlSet\Services\mchInjDrv

Command Service: Settings (Registry key, fixed)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\cmdService\\SYSTEM\CurrentControlSet\Services\mchInjDrv

Command Service: Settings (Registry key, fixing failed)
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cmdService

Zeno: Executable (File, fixed)
C:\WINDOWS\system32\dwdsregt.exe

Zeno: Text file (File, fixed)
C:\WINDOWS\system32\msnav32.ax

WildTangent: Settings (Registry value, fixed)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Java VM\ClassPath=...;C:\WINDOWS\wt\webdriver\wtdmmpi.jar...

MediaPlex: Tracking cookie (Internet Explorer: Michael) (Cookie, fixed)


DoubleClick: Tracking cookie (Internet Explorer: Michael) (Cookie, fixed)


HitBox: Tracking cookie (Internet Explorer: Michael) (Cookie, fixed)


Avenue A, Inc.: Tracking cookie (Internet Explorer: Michael) (Cookie, fixed)



--- Spybot - Search & Destroy version: 1.4 (build: 20050523) ---

2005-05-31 blindman.exe (1.0.0.1)
2005-05-31 SpybotSD.exe (1.4.0.3)
2005-05-31 TeaTimer.exe (1.4.0.2)
2006-06-19 unins000.exe (51.41.0.0)
2005-05-31 Update.exe (1.4.0.0)
2006-02-06 advcheck.dll (1.0.2.0)
2005-05-31 aports.dll (2.1.0.0)
2005-05-31 borlndmm.dll (7.0.4.453)
2005-05-31 delphimm.dll (7.0.4.453)
2005-05-31 SDHelper.dll (1.4.0.0)
2006-02-20 Tools.dll (2.0.0.2)
2005-05-31 UnzDll.dll (1.73.1.1)
2005-05-31 ZipDll.dll (1.73.2.0)
2006-06-16 Includes\Cookies.sbi (*)
2006-06-16 Includes\Dialer.sbi (*)
2006-06-16 Includes\Hijackers.sbi (*)
2006-06-16 Includes\Keyloggers.sbi (*)
2006-06-16 Includes\Malware.sbi (*)
2006-06-16 Includes\PUPS.sbi (*)
2006-06-16 Includes\Revision.sbi (*)
2006-06-16 Includes\Security.sbi (*)
2006-06-16 Includes\Spybots.sbi (*)
2005-02-17 Includes\Tracks.uti
2006-06-16 Includes\Trojans.sbi (*)

mcmill3
2006-06-20, 04:42
Sorry guys, but this is a report from Spyware Doctor, not sure how reliable the app is. It does look like I'm infected pretty good from the log below. Any help is appreciated.


Spyware Doctor Activity Report
Generated on 6/19/2006 8:44:12 PM Spyware Doctor

Infection Name Location Risk

Zeno Search Assistant c:\documents and settings\michael.wk-steelers\start menu\programs\startup\z_start.lnk High
PurityScan C:\Program Files\Common Files\MANTEC~1\winspool.exe High
TargetSavers C:\Program Files\Common Files\uqoq\uqoqd\class-barrel High
TargetSavers C:\Program Files\Common Files\uqoq\uqoqd\vocabulary High
Maxifiles C:\Program Files\windows\WinUpdate.fld High
6A90-4A0B-B101-0CEB450229E8}\RP1111\snapshot\MFEX-4.DAT Elevated
DSSAgent C:\WINDOWS\bbstore\DSS High
Trojan.VB.TG C:\WINDOWS\SYSC00.exe Medium
SurfSideKick C:\WINDOWS\system32\bk.exe High
Zeno Search Assistant C:\WINDOWS\system32\dwdsregt.exe High
Zeno Search Assistant C:\WINDOWS\system32\msnav32.ax High
Zeno Search Assistant C:\WINDOWS\system32\pmdsregq.exe High
LinkMaker Hijacker C:\WINDOWS\system32\x3cqp0.dll Elevated
PurityScan C:\WINDOWS\system32\XPLORE~1.EXE High
I-Search Desktop Search Toolbar C:\WINDOWS\TSZB\nmt1.vbs Elevated
Trojan.VB.TG C:\WINDOWS\uni_eh.exe Medium
Trojan.VB.TG C:\WINDOWS\unin101.exe Medium
Enbrowser C:\WINDOWS\Uninst2.htm Elevated
Enbrowser C:\WINDOWS\Unist1.htm Elevated
IEPlugin c:\windows\wininit.ini##c:\windows\wupdsnff.exe High
Adware.Defender dfndr.exe (C:\dfndr.exe) Elevated
Zeno Search Assistant dwdsregt.exe (c:\windows\system32\dwdsregt.exe) High
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F} Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}## Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32 Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32## Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32##ThreadingModel Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\ProgID Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\ProgID## Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\VersionIndependentProgID Elevated
LinkMaker Hijacker HKCR\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\VersionIndependentProgID## Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB} Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}## Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32 Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32## Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32##ThreadingModel Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\ProgID Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\ProgID## Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\VersionIndependentProgID Elevated
LinkMaker Hijacker HKCR\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\VersionIndependentProgID## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok.1 Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok.1## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok.1\CLSID Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok.1\CLSID## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok\CLSID Elevated
LinkMaker Hijacker HKCR\Fseytdc.Ariaqudok\CLSID## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt.1 Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt.1## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt.1\CLSID Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt.1\CLSID## Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt\CLSID Elevated
LinkMaker Hijacker HKCR\Fseytdc.Yvakt\CLSID## Elevated
Maxifiles HKCR\MyToolBar.MyToolBarObj High
Maxifiles HKCR\MyToolBar.MyToolBarObj## High
Maxifiles HKCR\MyToolBar.MyToolBarObj.1 High
Maxifiles HKCR\MyToolBar.MyToolBarObj.1## High
Maxifiles HKCR\MyToolBar.MyToolBarObj.1\CLSID High
Maxifiles HKCR\MyToolBar.MyToolBarObj.1\CLSID## High
Maxifiles HKCR\MyToolBar.MyToolBarObj\CLSID High
Maxifiles HKCR\MyToolBar.MyToolBarObj\CLSID## High
Maxifiles HKCR\MyToolBar.MyToolBarObj\CurVer High
Maxifiles HKCR\MyToolBar.MyToolBarObj\CurVer## High
Maxifiles HKCU\Software\Microsoft\Internet Explorer\MenuExt\&MyToolBar Search High
Maxifiles HKCU\Software\Microsoft\Internet Explorer\MenuExt\&MyToolBar Search## High
Maxifiles HKCU\Software\Microsoft\Internet Explorer\MenuExt\&MyToolBar Search##Contexts High
Backdoor.Rbot.Gen HKCU\Software\Microsoft\OLE##winlog High
Altnet Software HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Altnet Elevated
Altnet Software HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Altnet## Elevated
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A} High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}## High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore## High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore##Blocked High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore##Count High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore##Time High
MediaMotor HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5526B4C6-63D6-41A1-9783-0FABF529859A}\iexplore##Type High
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F} Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}## Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\iexplore Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\iexplore## Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\iexplore##Count Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\iexplore##Time Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\iexplore##Type Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66} Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}## Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}\iexplore Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}\iexplore## Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}\iexplore##Count Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}\iexplore##Time Elevated
LinkMaker Hijacker HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E5E2A3E7-00FE-4D31-A030-A10799DDCA66}\iexplore##Type Elevated
Trojan.Crypt.E HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run##WinUpdate.exe High
Common Components for Trojans HKCU\Software\System\sysuid Medium
Common Components for Trojans HKCU\Software\System\sysuid## Medium
Common Components for Trojans HKCU\Software\System\sysuid##uid Medium
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F} Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32 Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\InprocServer32##ThreadingModel Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\ProgID Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\ProgID## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\VersionIndependentProgID Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{AE0ECC2F-0C33-494C-8B22-B57A7763027F}\VersionIndependentProgID## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB} Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32 Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\InprocServer32##ThreadingModel Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\ProgID Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\ProgID## Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\VersionIndependentProgID Elevated
LinkMaker Hijacker HKLM\Software\Classes\CLSID\{DA28E0DB-229C-4003-827E-96AE15AD90FB}\VersionIndependentProgID## Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok## Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok.1 Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok.1## Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok.1\CLSID Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok.1\CLSID## Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok\CLSID Elevated
LinkMaker Hijacker HKLM\SOFTWARE\Classes\Fseytdc.Ariaqudok\CLSID## WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC## Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000 Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000## Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##Class Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##ClassGUID Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##ConfigFlags Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##DeviceDesc Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##Legacy Elevated
WinTools HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINTOOLSSVC\0000##Service Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService## Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##DependOnGroup Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##DependOnService Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##Description Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##DisplayName Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ErrorControl Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ImagePath Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##ObjectName Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##Start Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService##Type Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum## Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##0 Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##Count Elevated
I-Search Desktop Search Toolbar HKLM\SYSTEM\CurrentControlSet\Services\cmdService\Enum##NextInstance Elevated
Trojan.VB.TG SYSC00.exe (C:\WINDOWS\SYSC00.exe) Medium

CalamityJane
2006-06-21, 23:57
Hi mcmill3, welcome! :)

Are you still needing help? If so, please post a fresh HijackThis log to this thread. I'm now subscribed to your topic here and will get a notice when you reply :)

tashi
2006-06-29, 20:47
This topic is closed due to lack of a response to helper. :scratch:

If you need it re-opened please send me a pm and provide a link to the thread.

Applies only to the original topic starter.