citywomanpg
New member
Hi I have both the Trojan.Vundo and Vasya[1] on my computer. I've been running Norton AntiVirus which has flagged them in realtime protection but is unable to clear it. I've gone through several iterations of finding the file that Norton has indicated and clearing it manually from several locations but they keep coming back with different names.
I've run SpyBot several times and cleared the red problems, also Immunized but they keep coming back!
Because it seemed that my Internet Explorer had been hijacked I uninstalled it so am not able to run the Kaspersky online scan.
However I did run the HJT (log below). Also I'm posting the info that Norton gave me for when it found the Vasya[1] and also pasting the virus history information I exported from Norton for today. I've been battling this for a week now and can post all of that history if you need it. I am desperate for your help!
Also, somethings seem to have changed where the LiveUpdate for Norton is not able to connect to the server and download updated definitions even when I'm connected to the internet. I connect wirelessly to my router and have no trouble getting online with Firefox but LiveUpdate cannot seem to detect and go online.
I keep getting a popup that resembles something IE normally generates asking me if I want to "connect" or "work offline". As soon as I choose "connect" then I can afterwards run LiveUpdate but not otherwise.
*****************
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Downloader
File: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\vasya[1]
Location: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP
Computer: PGLAPTOP
User: user
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Mon Nov 05 19:09:11 2007
This is the description of the file in the Temporary Internet Files folder:
hxxx://82.98.235.78/netob/vasya.exe?uid=B132C25085D211DC8F72150027FAFFFF&guid=9991AF41DD2B4FBEB3F51DAA5B1DDD66
***********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:34:58 PM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\AEIWLSTA.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.continental.att.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\StorageGuard\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE START
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [e021aaec] rundll32.exe "C:\WINDOWS\system32\ijhvfpdd.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlueSoleil.lnk.disabled
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Update ThinkPad Software - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\ThinkPad\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) -
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} -
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://akonix.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpControl.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} -
O16 - DPF: {F545C0D0-4327-48FF-B27F-2AFE254E4FF2} (ActiveFrame Object) - http://icu.riverstyx.net/icumediacontrol.cab?
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://D:\CDVIEWER\CdViewer.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
--
End of file - 8656 bytes
******************
History from Norton of viruses found:
Date,Filename,Virus Name,Virus Type,Action Taken,Computer,User,Original Location,Status,Current Location,Primary Action,Secondary Action,Scan Type
11/5/2007 2:10:15 PM,gdnfvxtr.dll,Trojan.Vundo,File,Quarantined,PGLAPTOP,user,C:\DOCUME~1\user\LOCALS~1\Temp\,Infected,Quarantine,Clean virus from file,Quarantine infected file,Realtime scan
11/5/2007 2:10:15 PM,upd32_v13[1],Trojan.Vundo,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\Y99IZAH0\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\Y99IZAH0\,Clean virus from file,Quarantine infected file,Realtime scan
11/5/2007 2:07:13 PM,vasya[1],Downloader,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\,Clean virus from file,Quarantine infected file,Realtime scan
11/4/2007 7:01:32 PM,vasya[1],Downloader,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\FECZJ945\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\FECZJ945\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:33:03 AM,rqrstst.dll,Trojan.Vundo,File,Quarantined,PGLAPTOP,user,C:\WINDOWS\system32\,Infected,Quarantine,Clean virus from file,Quarantine infected file,Manual scan
11/1/2007 12:22:51 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:43 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:39 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:36 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:32 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:28 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:25 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:23 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
I've run SpyBot several times and cleared the red problems, also Immunized but they keep coming back!
Because it seemed that my Internet Explorer had been hijacked I uninstalled it so am not able to run the Kaspersky online scan.
However I did run the HJT (log below). Also I'm posting the info that Norton gave me for when it found the Vasya[1] and also pasting the virus history information I exported from Norton for today. I've been battling this for a week now and can post all of that history if you need it. I am desperate for your help!
Also, somethings seem to have changed where the LiveUpdate for Norton is not able to connect to the server and download updated definitions even when I'm connected to the internet. I connect wirelessly to my router and have no trouble getting online with Firefox but LiveUpdate cannot seem to detect and go online.
I keep getting a popup that resembles something IE normally generates asking me if I want to "connect" or "work offline". As soon as I choose "connect" then I can afterwards run LiveUpdate but not otherwise.
*****************
Scan type: Realtime Protection Scan
Event: Virus Found!
Virus name: Downloader
File: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\vasya[1]
Location: C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP
Computer: PGLAPTOP
User: user
Action taken: Clean failed : Quarantine failed : Access denied
Date found: Mon Nov 05 19:09:11 2007
This is the description of the file in the Temporary Internet Files folder:
hxxx://82.98.235.78/netob/vasya.exe?uid=B132C25085D211DC8F72150027FAFFFF&guid=9991AF41DD2B4FBEB3F51DAA5B1DDD66
***********************
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:34:58 PM, on 11/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\tp4serv.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\NavNT\vptray.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\WINDOWS\system32\AEIWLSTA.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.continental.att.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;<local>
O3 - Toolbar: Pa&nicware Pop-Up Stopper - {7E82235C-F31E-46CB-AF9F-1ADD94C585FF} - C:\Program Files\Panicware\Pop-Up Stopper\pstopper.dll
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [TrackPointSrv] tp4serv.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\StorageGuard\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [AEIWLSTA.EXE] AEIWLSTA.EXE START
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [e021aaec] rundll32.exe "C:\WINDOWS\system32\ijhvfpdd.dll",b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BlueSoleil.lnk.disabled
O4 - Global Startup: Exif Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Update ThinkPad Software - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\ThinkPad\PkgMgr\\PkgMgr.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} -
O16 - DPF: {74FFE28D-2378-11D5-990C-006094235084} (IBM Access Support) - http://www-307.ibm.com/pc/support/IbmEgath.cab
O16 - DPF: {8FD68625-2346-418A-8899-67CB36B1917F} (McciSM Class) -
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} -
O16 - DPF: {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.5.0_01) -
O16 - DPF: {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.5.0_02) -
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://akonix.webex.com/client/T23L/webex/ieatgpc.cab
O16 - DPF: {E598AC61-4C6F-4F4D-877F-FAC49CA91FA3} (acpRunner Class) - https://www-307.ibm.com/pc/support/access/aslibmain/content/AcpControl.cab
O16 - DPF: {E6EB803E-DD89-11D3-80C4-0050DA2E09D0} -
O16 - DPF: {F545C0D0-4327-48FF-B27F-2AFE254E4FF2} (ActiveFrame Object) - http://icu.riverstyx.net/icumediacontrol.cab?
O16 - DPF: {FC11A119-C2F7-46F4-9E32-937ABA26816E} (AMI DicomDir TreeView Control 2.1) - file://D:\CDVIEWER\CdViewer.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
--
End of file - 8656 bytes
******************
History from Norton of viruses found:
Date,Filename,Virus Name,Virus Type,Action Taken,Computer,User,Original Location,Status,Current Location,Primary Action,Secondary Action,Scan Type
11/5/2007 2:10:15 PM,gdnfvxtr.dll,Trojan.Vundo,File,Quarantined,PGLAPTOP,user,C:\DOCUME~1\user\LOCALS~1\Temp\,Infected,Quarantine,Clean virus from file,Quarantine infected file,Realtime scan
11/5/2007 2:10:15 PM,upd32_v13[1],Trojan.Vundo,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\Y99IZAH0\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\Y99IZAH0\,Clean virus from file,Quarantine infected file,Realtime scan
11/5/2007 2:07:13 PM,vasya[1],Downloader,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\CNR3EKHP\,Clean virus from file,Quarantine infected file,Realtime scan
11/4/2007 7:01:32 PM,vasya[1],Downloader,File,Left alone,PGLAPTOP,user,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\FECZJ945\,Infected,C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\FECZJ945\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:33:03 AM,rqrstst.dll,Trojan.Vundo,File,Quarantined,PGLAPTOP,user,C:\WINDOWS\system32\,Infected,Quarantine,Clean virus from file,Quarantine infected file,Manual scan
11/1/2007 12:22:51 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:43 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:39 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:36 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:32 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:28 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:25 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
11/1/2007 12:22:23 AM,hggghhg.dll,Trojan.Vundo,File,Left alone,PGLAPTOP,SYSTEM,C:\WINDOWS\system32\,Infected,C:\WINDOWS\system32\,Clean virus from file,Quarantine infected file,Realtime scan
Last edited by a moderator: