aurora and seeve pop ups, adware report according to your requests |
![]() ![]() |
aurora and seeve pop ups, adware report according to your requests |
Jun 26 2005, 11:46 AM
Post
#1
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
Edit: Old build and incomplete log,
|
|
|
Jun 26 2005, 11:58 AM
Post
#2
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Hi and welcome tarina
Ad-aware SE build 1.06r1 is the most current version, As you are not using the latest version, please could you chose a download site to download the latest version. Download site list Just make sure you uninstall any old version of Ad-Aware before installing SE. After installing SE, then update your definition file Please then rescan your computer with the full system scan option And post your results here. Be sure and post the complete log please |
|
|
Jun 27 2005, 04:45 PM
Post
#3
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
I followed your new directions, here is the new scan log. I hope it is complete, and I truly appreciate your help in this matter.
Thanks again, Tarina Logfile removed: Incorrect Logfile type posted This post has been edited by Andy_veal: Jun 28 2005, 09:37 AM |
|
|
| Guest_Andy_veal_* |
Jun 28 2005, 09:36 AM
Post
#4
|
|
|
QUOTE Please then rescan your computer with the full system scan option Sorry about this but you posted a Smart mode scan, please follow Don's advice of selecting the full system scan option and posting your new logfile here. Thanks |
|
|
Jun 28 2005, 06:10 PM
Post
#5
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
Once again I'm sorry that I missed a step, this should be done correctly. I thank you for your patience with me and appreciate your help
Tarina Ad-Aware SE Build 1.06r1 Logfile Created on:Tuesday, June 28, 2005 6:59:01 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R51 21.06.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R51 21.06.2005 Internal build : 59 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 483435 Bytes Total size : 1461660 Bytes Signature data size : 1429955 Bytes Reference data size : 31193 Bytes Signatures total : 40756 CSI Fingerprints total : 906 CSI data size : 31253 Bytes Target categories : 15 Target families : 694 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Non Intel Memory available:50 % Total physical memory:1046960 kb Available physical memory:516320 kb Total page file size:2518736 kb Available on page file:2004544 kb Total virtual memory:2097024 kb Available virtual memory:2045692 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Play sound at scan completion if scan locates critical objects 6-28-2005 6:59:01 PM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 744 ThreadCreationTime : 6-28-2005 10:06:21 PM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 820 ThreadCreationTime : 6-28-2005 10:06:23 PM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 844 ThreadCreationTime : 6-28-2005 10:06:23 PM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 888 ThreadCreationTime : 6-28-2005 10:06:23 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 900 ThreadCreationTime : 6-28-2005 10:06:23 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 1040 ThreadCreationTime : 6-28-2005 10:06:24 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 1120 ThreadCreationTime : 6-28-2005 10:06:24 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1156 ThreadCreationTime : 6-28-2005 10:06:24 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [evteng.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe" ProcessID : 1192 ThreadCreationTime : 6-28-2005 10:06:24 PM BasePriority : Normal FileVersion : 9, 0, 1, 12 ProductVersion : 9, 0, 0, 0 ProductName : EvtEng Module CompanyName : Intel Corporation FileDescription : EvtEng Module InternalName : EvtEng LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : EvtEng.EXE #:10 [s24evmon.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" ProcessID : 1288 ThreadCreationTime : 6-28-2005 10:06:25 PM BasePriority : Normal FileVersion : 9, 0, 1, 41 ProductVersion : 9, 0, 0, 0 ProductName : Mobile Unit Support Service CompanyName : Intel Corporation FileDescription : Event Monitor - Supports driver extensions to NIC Driver for wireless adapters. InternalName : S24EvMon LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : S24EvMon.exe #:11 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k NetworkService ProcessID : 1452 ThreadCreationTime : 6-28-2005 10:06:25 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k LocalService ProcessID : 1480 ThreadCreationTime : 6-28-2005 10:06:25 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:13 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1728 ThreadCreationTime : 6-28-2005 10:06:25 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe VX2 Object Recognized! Type : Process Data : DrPMon.dll TAC Rating : 10 Category : Malware Comment : Object : C:\WINDOWS\system32\ FileVersion : 1, 0, 0, 5 ProductVersion : 1, 0, 0, 0 ProductName : DrPMon PrintMonitor CompanyName : Direct Revenue FileDescription : DrPMon PrintMonitor InternalName : DrPMon LegalCopyright : Copyright © 2005 OriginalFilename : DrPMon.dll #:14 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.exe Command Line : Explorer.exe C:\WINDOWS\Nail.exe ProcessID : 1952 ThreadCreationTime : 6-28-2005 10:06:26 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:15 [vptray.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe Command Line : "C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" ProcessID : 2004 ThreadCreationTime : 6-28-2005 10:06:26 PM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Symantec AntiVirus CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus LegalCopyright : Copyright © Symantec Corporation 1991-2003 #:16 [vmconsole.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin ProcessID : 2012 ThreadCreationTime : 6-28-2005 10:06:26 PM BasePriority : Normal FileVersion : 3.1.00.06230 ProductVersion : 3.1.00.00000 ProductName : VAIO Media Integrated Server CompanyName : Sony Corporation FileDescription : VAIO Media Console InternalName : VMConsole LegalCopyright : Copyright 2002 2003 2004 Sony Corp. OriginalFilename : VMConsole.EXE #:17 [vaioupdt.exe] ModuleName : C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe Command Line : "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary ProcessID : 2036 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal #:18 [switcher.exe] ModuleName : C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe Command Line : "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" ProcessID : 152 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 3, 0, 0, 10250 ProductVersion : 3, 0, 0, 10250 ProductName : Wireless Switch Setting Utility CompanyName : Sony Corporation FileDescription : Wireless Switch Setting Utility InternalName : Wireless Switch Setting Utility LegalCopyright : Copyright 2004 Sony Corp. OriginalFilename : Switcher.exe Comments : Wireless Switch Setting Utility #:19 [ssaad.exe] ModuleName : C:\PROGRA~1\sony\SONICS~1\SsAAD.exe Command Line : "C:\PROGRA~1\sony\SONICS~1\SsAAD.exe" ProcessID : 168 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 3.0.00.13241 FileDescription : SonicStage Atrac Hard Disk Monitor InternalName : SonicStage Atrac Hard Disk Monitor LegalCopyright : Copyright 2005 Sony Corporation #:20 [spmgr.exe] ModuleName : C:\Program Files\Sony\VAIO Power Management\SPMgr.exe Command Line : "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" ProcessID : 180 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 1.6.0.10190 ProductVersion : 1.6.0 ProductName : Sony Power Management CompanyName : Sony Corporation FileDescription : SPM Module LegalCopyright : © Sony Corporation. All rights reserved. #:21 [shstat.exe] ModuleName : C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE Command Line : "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE ProcessID : 144 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal #:22 [seeve.exe] ModuleName : C:\WINDOWS\seeve.exe Command Line : "C:\WINDOWS\seeve.exe" ProcessID : 196 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 6.04 ProductVersion : 6.04 ProductName : pop64 CompanyName : Network1 InternalName : seeve OriginalFilename : seeve.exe #:23 [picsvr.exe] ModuleName : C:\WINDOWS\system32\picsvr\picsvr.exe Command Line : "C:\WINDOWS\system32\picsvr\picsvr.exe" ProcessID : 232 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal #:24 [nsvsvc.exe] ModuleName : C:\WINDOWS\system32\nsvsvc\nsvsvc.exe Command Line : "C:\WINDOWS\system32\nsvsvc\nsvsvc.exe" ProcessID : 352 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 2.17.0000 ProductVersion : 2, 1, 7, 0 #:25 [updaterui.exe] ModuleName : C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe Command Line : "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" ProcessID : 452 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : Common User Interface InternalName : UpdaterUI LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : UpdaterUI.exe #:26 [defwatch.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe Command Line : C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe ProcessID : 468 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Virus Definition Daemon InternalName : DefWatch LegalCopyright : Copyright © 1998 Symantec Corporation OriginalFilename : DefWatch.exe #:27 [isbmgr.exe] ModuleName : C:\Program Files\Sony\ISB Utility\ISBMgr.exe Command Line : "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" ProcessID : 480 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal #:28 [dkservice.exe] ModuleName : C:\Program Files\Executive Software\Diskeeper\DkService.exe Command Line : "C:\Program Files\Executive Software\Diskeeper\DkService.exe" ProcessID : 540 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 8.0.459.0 ProductVersion : 8.0.459.0 ProductName : Diskeeper Disk Defragmenter CompanyName : Executive Software International, Inc. FileDescription : DKSERVICE.EXE InternalName : DKSERVICE LegalCopyright : © 1995-2003 Executive Software Int'l, Inc. OriginalFilename : DKSERVICE #:29 [apoint.exe] ModuleName : C:\Program Files\Apoint\Apoint.exe Command Line : "C:\Program Files\Apoint\Apoint.exe" ProcessID : 632 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 5.5.7.136 ProductVersion : 5.5.7.136 ProductName : Alps Pointing-device Driver CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver InternalName : Alps Pointing-device Driver LegalCopyright : Copyright © 1999-2003 Alps Electric Co., Ltd. OriginalFilename : Apoint.exe #:30 [frameworkservice.exe] ModuleName : C:\Program Files\Network Associates\Common Framework\FrameworkService.exe Command Line : "C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart ProcessID : 672 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : Framework Service InternalName : Framework LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : Framework.exe #:31 [acrotray.exe] ModuleName : C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe Command Line : "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" ProcessID : 688 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 6.0.1.2004121400 ProductVersion : 6.0.1.2004121400 ProductName : AcroTray - Adobe Acrobat Distiller helper application. CompanyName : Adobe Systems Inc. FileDescription : AcroTray InternalName : AcroTray LegalCopyright : Copyright 1984-2004 Adobe Systems Incorporated and its licensors. All rights reserved. OriginalFilename : AcroTray.exe #:32 [vstskmgr.exe] ModuleName : C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Command Line : "C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe" ProcessID : 720 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal #:33 [hpztsb11.exe] ModuleName : C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe Command Line : "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" ProcessID : 724 ThreadCreationTime : 6-28-2005 10:06:27 PM BasePriority : Normal FileVersion : 2.327.1.0 ProductVersion : 2.327.1.0 ProductName : HP DeskJet CompanyName : HP LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004 #:34 [mdm.exe] ModuleName : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Command Line : "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" ProcessID : 864 ThreadCreationTime : 6-28-2005 10:06:28 PM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:35 [hpwuschd2.exe] ModuleName : C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Command Line : "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ProcessID : 1072 ThreadCreationTime : 6-28-2005 10:06:28 PM BasePriority : Normal FileVersion : 2, 0, 39, 0 ProductVersion : 2, 0, 39, 0 ProductName : Hewlett-Packard hpwuSchd CompanyName : Hewlett-Packard Company FileDescription : hpwuSchd InternalName : hpwuSchd LegalCopyright : Copyright © 2003 OriginalFilename : hpwuSchd2.exe #:36 [hpcmpmgr.exe] ModuleName : C:\Program Files\HP\hpcoretech\hpcmpmgr.exe Command Line : "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" ProcessID : 1180 ThreadCreationTime : 6-28-2005 10:06:28 PM BasePriority : Normal FileVersion : 2.1.1.0 ProductVersion : 2.1.5 ProductName : hp coretech (COmponent REuse TECHnology) CompanyName : Hewlett-Packard Company FileDescription : HP Framework Component Manager Service InternalName : HPComponentManagerService module LegalCopyright : Copyright © Hewlett-Packard. 2002-2004 OriginalFilename : HpCmpMgr.exe #:37 [hphmon06.exe] ModuleName : C:\WINDOWS\system32\hphmon06.exe Command Line : "C:\WINDOWS\system32\hphmon06.exe" ProcessID : 1188 ThreadCreationTime : 6-28-2005 10:06:28 PM BasePriority : Normal FileVersion : 6,0,72 ProductVersion : 6,0,72 ProductName : HP Photosmart CompanyName : Hewlett-Packard FileDescription : HPHmon06 InternalName : HPHmon06 LegalCopyright : Copyright © 2004 OriginalFilename : HPHmon06.exe #:38 [rtvscan.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe Command Line : C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe ProcessID : 1296 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Symantec AntiVirus CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus LegalCopyright : Copyright © Symantec Corporation 1991-2003 #:39 [qttask.exe] ModuleName : C:\Program Files\QuickTime\qttask.exe Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime ProcessID : 1356 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 6.4 ProductVersion : QuickTime 6.4 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2003 OriginalFilename : QTTask.exe #:40 [naprdmgr.exe] ModuleName : C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe Command Line : C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe -Embedding ProcessID : 1420 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : NAI Product Manager InternalName : Product Manager LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : naPrdMgr.exe #:41 [nvsvc32.exe] ModuleName : C:\WINDOWS\system32\nvsvc32.exe Command Line : C:\WINDOWS\system32\nvsvc32.exe ProcessID : 1444 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 6.14.10.7082 ProductVersion : 6.14.10.7082 ProductName : NVIDIA Driver Helper Service, Version 70.82 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 70.82 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:42 [zvfgyv.exe] ModuleName : c:\windows\system32\zvfgyv.exe Command Line : "c:\windows\system32\zvfgyv.exe" uuuwbnm ProcessID : 1536 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 1, 0, 7, 1 ProductVersion : 0, 0, 7, 0 ProductName : TODO: <Product name> CompanyName : TODO: <Company name> FileDescription : TODO: <File description> LegalCopyright : TODO: © <Company name>. All rights reserved. #:43 [msmsgs.exe] ModuleName : C:\Program Files\Messenger\msmsgs.exe Command Line : "C:\Program Files\Messenger\msmsgs.exe" /background ProcessID : 1548 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:44 [regsrvc.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe" ProcessID : 1576 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 9, 0, 1, 10 ProductVersion : 9, 0, 0, 0 ProductName : RegSrvc Module CompanyName : Intel Corporation FileDescription : RegSrvc Module InternalName : RegSrvc LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : RegSrvc.EXE Comments : Registry Interface for Intel Wireless Products #:45 [ctfmon.exe] ModuleName : C:\WINDOWS\system32\ctfmon.exe Command Line : "C:\WINDOWS\system32\ctfmon.exe" ProcessID : 1624 ThreadCreationTime : 6-28-2005 10:06:29 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:46 [wdfmgr.exe] ModuleName : C:\WINDOWS\system32\wdfmgr.exe Command Line : C:\WINDOWS\system32\wdfmgr.exe ProcessID : 2244 ThreadCreationTime : 6-28-2005 10:06:30 PM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:47 [apntex.exe] ModuleName : C:\Program Files\Apoint\Apntex.exe Command Line : "Apntex.exe" ProcessID : 2368 ThreadCreationTime : 6-28-2005 10:06:30 PM BasePriority : Normal FileVersion : 5.0.1.15 ProductVersion : 5.0.1.15 ProductName : Alps Pointing-device Driver for Windows NT/2000/XP CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP InternalName : Alps Pointing-device Driver for Windows NT/2000/XP LegalCopyright : Copyright © 1998-2003 Alps Electric Co., Ltd. OriginalFilename : ApntEx.exe #:48 [vesmgr.exe] ModuleName : C:\Program Files\Sony\VAIO Event Service\VESMgr.exe Command Line : "C:\Program Files\Sony\VAIO Event Service\VESMgr.exe" ProcessID : 2424 ThreadCreationTime : 6-28-2005 10:06:31 PM BasePriority : Normal FileVersion : 2.0.00.09300 ProductVersion : 2.0.00 ProductName : VAIO Event Service CompanyName : Sony Corporation FileDescription : VAIO Event Service (Service Module) InternalName : VESMgr.exe LegalCopyright : Copyright 2004,2005 Sony Corp. OriginalFilename : VESMgr.exe #:49 [sideact.exe] ModuleName : C:\Program Files\ACT\SideACT.exe Command Line : "C:\Program Files\ACT\SideACT.exe" /s ProcessID : 2456 ThreadCreationTime : 6-28-2005 10:06:31 PM BasePriority : Normal #:50 [vmisrv.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe" ProcessID : 2480 ThreadCreationTime : 6-28-2005 10:06:31 PM BasePriority : Normal #:51 [vcsw.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe" -RunBySCM ProcessID : 2496 ThreadCreationTime : 6-28-2005 10:06:31 PM BasePriority : Normal #:52 [vzcdbsvc.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" ProcessID : 2700 ThreadCreationTime : 6-28-2005 10:06:32 PM BasePriority : Normal #:53 [vzfw.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe" ProcessID : 2804 ThreadCreationTime : 6-28-2005 10:06:33 PM BasePriority : Normal #:54 [hpqgalry.exe] ModuleName : C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe Command Line : "C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe" -s ProcessID : 2872 ThreadCreationTime : 6-28-2005 10:06:33 PM BasePriority : Normal #:55 [sv_httpd.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" ProcessID : 3792 ThreadCreationTime : 6-28-2005 10:06:37 PM BasePriority : Normal FileVersion : 3.0.00.06160 ProductVersion : 3.0.00.13260 ProductName : SV_Httpd.exe CompanyName : Sony Corporation FileDescription : Sony HTTP Server InternalName : SV_Httpd LegalCopyright : Copyright 2002, 2003, 2004 Sony Corp. OriginalFilename : SV_Httpd.exe #:56 [upnpframework.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe" ProcessID : 3832 ThreadCreationTime : 6-28-2005 10:06:37 PM BasePriority : Normal FileVersion : 6.0.00.06220 ProductVersion : 6.0.00.06220 ProductName : UPnPFramework.exe CompanyName : Sony Corporation FileDescription : Sony UPnP Framework InternalName : UPnPFramework LegalCopyright : Copyright 2002,2003,2004 Sony Corp. OriginalFilename : UPnPFramework.exe #:57 [ssscsisv.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe Command Line : "C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe" ProcessID : 3880 ThreadCreationTime : 6-28-2005 10:06:38 PM BasePriority : Normal FileVersion : 3.0.00.13241 ProductVersion : 3.0.00 ProductName : SonicStage CompanyName : Sony Corporation FileDescription : SonicStage Scsi I/F Server InternalName : SSScsiSV LegalCopyright : Copyright 2005 Sony Corporation OriginalFilename : SSScsiSV.EXE #:58 [wscntfy.exe] ModuleName : C:\WINDOWS\system32\wscntfy.exe Command Line : C:\WINDOWS\system32\wscntfy.exe ProcessID : 1364 ThreadCreationTime : 6-28-2005 10:06:40 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Security Center Notification App InternalName : wscntfy.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wscntfy.exe #:59 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 2192 ThreadCreationTime : 6-28-2005 10:06:41 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:60 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\iexplore.exe Command Line : "C:\Program Files\Internet Explorer\iexplore.exe" ProcessID : 3596 ThreadCreationTime : 6-28-2005 10:06:44 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:61 [pedev.exe] ModuleName : C:\Program Files\PeDevice\PeDev.exe Command Line : "C:\Program Files\PeDevice\PeDev.exe" -Embedding ProcessID : 3876 ThreadCreationTime : 6-28-2005 10:06:48 PM BasePriority : Normal FileVersion : 1.0.8 ProductVersion : 1.0.8 ProductName : PopUp Engine FileDescription : PopUp engine InternalName : pedev.exe LegalCopyright : 2005 ©. All rights reserved. OriginalFilename : pedev.exe #:62 [wuauclt.exe] ModuleName : C:\WINDOWS\system32\wuauclt.exe Command Line : "C:\WINDOWS\system32\wuauclt.exe" ProcessID : 2252 ThreadCreationTime : 6-28-2005 10:08:34 PM BasePriority : Normal FileVersion : 5.8.0.2469 built by: lab01_n(wmbla) ProductVersion : 5.8.0.2469 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe #:63 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 3612 ThreadCreationTime : 6-28-2005 10:10:37 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:64 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 2124 ThreadCreationTime : 6-28-2005 10:15:42 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:65 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 3412 ThreadCreationTime : 6-28-2005 10:20:38 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:66 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\iexplore.exe Command Line : "C:\DOCUME~1\LEEMEN~1\LOCALS~1\Temp\~wmvtmp2\Index.html" ProcessID : 2572 ThreadCreationTime : 6-28-2005 10:22:35 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:67 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 948 ThreadCreationTime : 6-28-2005 10:36:34 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:68 [outlook.exe] ModuleName : C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE Command Line : "C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE" /recycle ProcessID : 1104 ThreadCreationTime : 6-28-2005 10:40:55 PM BasePriority : Normal #:69 [winword.exe] ModuleName : C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE Command Line : "C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE" -Embedding ProcessID : 3408 ThreadCreationTime : 6-28-2005 10:41:01 PM BasePriority : Normal #:70 [excel.exe] ModuleName : C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE Command Line : "C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE" /e ProcessID : 4008 ThreadCreationTime : 6-28-2005 10:44:45 PM BasePriority : Normal #:71 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 3616 ThreadCreationTime : 6-28-2005 10:47:58 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:72 [iexplore.exe] ModuleName : C:\Program Files\Internet Explorer\IEXPLORE.EXE Command Line : "C:\Program Files\Internet Explorer\IEXPLORE.EXE" ProcessID : 3564 ThreadCreationTime : 6-28-2005 10:47:58 PM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Internet Explorer InternalName : iexplore LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : IEXPLORE.EXE #:73 [vzhardwareresourcemanager.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe" ProcessID : 3776 ThreadCreationTime : 6-28-2005 11:11:09 PM BasePriority : Normal #:74 [hpzipm12.exe] ModuleName : C:\WINDOWS\system32\HPZipm12.exe Command Line : C:\WINDOWS\system32\HPZipm12.exe ProcessID : 1784 ThreadCreationTime : 6-28-2005 11:57:06 PM BasePriority : Normal FileVersion : 8, 0, 0, 0 ProductVersion : 8, 0, 0, 0 ProductName : HP PML CompanyName : HP FileDescription : PML Driver InternalName : PmlDrv LegalCopyright : Copyright © 1998, 1999 Hewlett-Packard Company OriginalFilename : PmlDrv.exe #:75 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 3072 ThreadCreationTime : 6-28-2005 11:57:35 PM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 1 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» ImIServer IEPlugin Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : clsid\{01f44a8a-8c97-4325-a378-76e68dc4ab2e} ImIServer IEPlugin Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : interface\{3e589169-86ad-44fe-b426-f0bf105d5582} ImIServer IEPlugin Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : typelib\{57add57b-173e-418a-8f70-17e5c9f2bcc9} ImIServer IEPlugin Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : wbho.band ImIServer IEPlugin Object Recognized! Type : Regkey Data : TAC Rating : 5 Category : Data Miner Comment : Rootkey : HKEY_CLASSES_ROOT Object : wbho.band.1 VX2 Object Recognized! Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3d5OfSInst VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3n5trMsgSDisp VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky1S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky2S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky3S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky4S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC1o3d5eOfSFinalAd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3i5m7eOfSFinalAd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUD3s5tSSEnd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AU3N5a7tionSCode VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUP3D5om VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSCheckSIn VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSMots VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUM3o5deSSync VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSCab VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSEx VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSLstest VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUB3D5om VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUE3v5nt VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSBath VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSysSInf VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUL3n5Title VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3u5rrentSMode VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3n5tFyl VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_US |
|
|
| Guest_Andy_veal_* |
Jun 29 2005, 04:23 PM
Post
#6
|
|
|
Hello and Welcome
Ad-aware has found objects on your computer If you chose to clean your computer from what Ad-aware found please follow these instructions below… Please make sure that you are using the * SE1R51 21.06.2005 * definition file. Please launch Ad-Aware SE and click on the gear to access the Configuration Menu. Please make sure that this setting is applied. Click on Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion". Disconnect from the internet (for broadband/cable users, it is recommended that you disconnect the cable connection) and close all open browsers or other programs you have running. Please then boot into Safe Mode To clean your machine, it is highly recommended that you clean the following directory contents (but not the directory folder): Please run CCleaner to assist in this process. Download CCleaner (Setup: go to >options > settings > Uncheck "Only delete files in Windows Temp folders older than 48 hours" for cleaning malware files!) * C:\Windows\Temp\ * C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\ <- This will delete all your cached internet content including cookies. * C:\Documents and Settings\<Your Profile>\Local Settings\Temp\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files\ * C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp\ * Empty your "Recycle Bin". Please run Ad-Aware SE from the command lines shown in the instructions shown below. Click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" /full +procnuke (For the Professional version) "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" /full +procnuke (For the Plus version) "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +procnuke (For the Personal version) Click OK. Please note that the path above is of the default installion location for Ad-aware SE, if this is different, please adjust it to the location that you have installed it to. When the scan has completed, select Next. In the Scanning Results window, select the "Scan Summary" tab. Check the box next to each "target family" you wish to remove. Click next, Click OK. If problems are caused by deleting a family, please leave it. Please shutdown/restart your computer after removal, run a new full scan and post the results as a reply. Do not launch any programs or connect to the internet at this time. Please then copy & paste the complete log file here. Don't quarantine or remove anything at this time, just post a complete logfile. This can sometimes takes 2-3 posts to get it all posted, once the "Summary of this scan" information is shown, you have posted all of your logfile. Please remember when posting another logfile keep "Search for negligible risk entries" deselected as negligible risk entries (MRU's) are not considered to be a threat. This option can be changed when choosing your scan type. Please post back here Good luck Andy |
|
|
Jun 29 2005, 08:52 PM
Post
#7
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
Here is the latest log after following your directions, I am a little concerned about a pop up that came after rebooting and trying to log on to the internet to post this, It was called Registry Scan, and it downloaded to my computer and I didn't click anything. I removed it in the add/remove programs because it freaked me out. I just wanted to let you know about that, and I am still getting pop ups from aurora and seeve. Once again I thank you so much for your help and being patient with my very little computer knowledge. I hope you are having a great day!
Thanks again! Tarina Ad-Aware SE Build 1.06r1 Logfile Created on:Wednesday, June 29, 2005 9:34:22 PM Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R51 21.06.2005 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Definition File: ========================= Definitions File Loaded: Reference Number : SE1R51 21.06.2005 Internal build : 59 File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref File size : 483435 Bytes Total size : 1461660 Bytes Signature data size : 1429955 Bytes Reference data size : 31193 Bytes Signatures total : 40756 CSI Fingerprints total : 906 CSI data size : 31253 Bytes Target categories : 15 Target families : 694 Memory + processor status: ========================== Number of processors : 1 Processor architecture : Non Intel Memory available:62 % Total physical memory:1046960 kb Available physical memory:648072 kb Total page file size:2518736 kb Available on page file:2213648 kb Total virtual memory:2097024 kb Available virtual memory:2045764 kb OS:Microsoft Windows XP Home Edition Service Pack 2 (Build 2600) Ad-Aware SE Settings =========================== Set : Search for low-risk threats Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Obtain command line of scanned processes Set : Scan registry for all users instead of current user only Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Play sound at scan completion if scan locates critical objects 6-29-2005 9:34:22 PM - Scan started. (Full System Scan) Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] ModuleName : \SystemRoot\System32\smss.exe Command Line : n/a ProcessID : 780 ThreadCreationTime : 6-30-2005 2:32:43 AM BasePriority : Normal #:2 [csrss.exe] ModuleName : \??\C:\WINDOWS\system32\csrss.exe Command Line : C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestTh ProcessID : 828 ThreadCreationTime : 6-30-2005 2:32:44 AM BasePriority : Normal #:3 [winlogon.exe] ModuleName : \??\C:\WINDOWS\system32\winlogon.exe Command Line : winlogon.exe ProcessID : 852 ThreadCreationTime : 6-30-2005 2:32:45 AM BasePriority : High #:4 [services.exe] ModuleName : C:\WINDOWS\system32\services.exe Command Line : C:\WINDOWS\system32\services.exe ProcessID : 896 ThreadCreationTime : 6-30-2005 2:32:45 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Services and Controller app InternalName : services.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : services.exe #:5 [lsass.exe] ModuleName : C:\WINDOWS\system32\lsass.exe Command Line : C:\WINDOWS\system32\lsass.exe ProcessID : 908 ThreadCreationTime : 6-30-2005 2:32:45 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k DcomLaunch ProcessID : 1052 ThreadCreationTime : 6-30-2005 2:32:45 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost -k rpcss ProcessID : 1128 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] ModuleName : C:\WINDOWS\System32\svchost.exe Command Line : C:\WINDOWS\System32\svchost.exe -k netsvcs ProcessID : 1164 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [evteng.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\EvtEng.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\EvtEng.exe" ProcessID : 1204 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 9, 0, 1, 12 ProductVersion : 9, 0, 0, 0 ProductName : EvtEng Module CompanyName : Intel Corporation FileDescription : EvtEng Module InternalName : EvtEng LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : EvtEng.EXE #:10 [s24evmon.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe" ProcessID : 1244 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 9, 0, 1, 41 ProductVersion : 9, 0, 0, 0 ProductName : Mobile Unit Support Service CompanyName : Intel Corporation FileDescription : Event Monitor - Supports driver extensions to NIC Driver for wireless adapters. InternalName : S24EvMon LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : S24EvMon.exe #:11 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k NetworkService ProcessID : 1296 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:12 [svchost.exe] ModuleName : C:\WINDOWS\system32\svchost.exe Command Line : C:\WINDOWS\system32\svchost.exe -k LocalService ProcessID : 1408 ThreadCreationTime : 6-30-2005 2:32:46 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:13 [explorer.exe] ModuleName : C:\WINDOWS\Explorer.exe Command Line : Explorer.exe C:\WINDOWS\Nail.exe ProcessID : 1696 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : EXPLORER.EXE #:14 [spoolsv.exe] ModuleName : C:\WINDOWS\system32\spoolsv.exe Command Line : C:\WINDOWS\system32\spoolsv.exe ProcessID : 1828 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:15 [defwatch.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe Command Line : C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe ProcessID : 1932 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Virus Definition Daemon InternalName : DefWatch LegalCopyright : Copyright © 1998 Symantec Corporation OriginalFilename : DefWatch.exe #:16 [dkservice.exe] ModuleName : C:\Program Files\Executive Software\Diskeeper\DkService.exe Command Line : "C:\Program Files\Executive Software\Diskeeper\DkService.exe" ProcessID : 1948 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 8.0.459.0 ProductVersion : 8.0.459.0 ProductName : Diskeeper Disk Defragmenter CompanyName : Executive Software International, Inc. FileDescription : DKSERVICE.EXE InternalName : DKSERVICE LegalCopyright : © 1995-2003 Executive Software Int'l, Inc. OriginalFilename : DKSERVICE #:17 [frameworkservice.exe] ModuleName : C:\Program Files\Network Associates\Common Framework\FrameworkService.exe Command Line : "C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart ProcessID : 1992 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : Framework Service InternalName : Framework LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : Framework.exe #:18 [vstskmgr.exe] ModuleName : C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe Command Line : "C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe" ProcessID : 2024 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal #:19 [mdm.exe] ModuleName : C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Command Line : "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE" ProcessID : 184 ThreadCreationTime : 6-30-2005 2:32:47 AM BasePriority : Normal FileVersion : 7.00.9466 ProductVersion : 7.00.9466 ProductName : Microsoft® Visual Studio .NET CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : mdm.exe #:20 [rtvscan.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe Command Line : C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe ProcessID : 236 ThreadCreationTime : 6-30-2005 2:32:48 AM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Symantec AntiVirus CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus LegalCopyright : Copyright © Symantec Corporation 1991-2003 #:21 [nvsvc32.exe] ModuleName : C:\WINDOWS\system32\nvsvc32.exe Command Line : C:\WINDOWS\system32\nvsvc32.exe ProcessID : 264 ThreadCreationTime : 6-30-2005 2:32:48 AM BasePriority : Normal FileVersion : 6.14.10.7082 ProductVersion : 6.14.10.7082 ProductName : NVIDIA Driver Helper Service, Version 70.82 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 70.82 InternalName : NVSVC LegalCopyright : © NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:22 [naprdmgr.exe] ModuleName : C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe Command Line : C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe -Embedding ProcessID : 292 ThreadCreationTime : 6-30-2005 2:32:48 AM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : NAI Product Manager InternalName : Product Manager LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : naPrdMgr.exe #:23 [regsrvc.exe] ModuleName : C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe Command Line : "C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe" ProcessID : 340 ThreadCreationTime : 6-30-2005 2:32:48 AM BasePriority : Normal FileVersion : 9, 0, 1, 10 ProductVersion : 9, 0, 0, 0 ProductName : RegSrvc Module CompanyName : Intel Corporation FileDescription : RegSrvc Module InternalName : RegSrvc LegalCopyright : Copyright © Intel Corporation 1999-2004 OriginalFilename : RegSrvc.EXE Comments : Registry Interface for Intel Wireless Products #:24 [wdfmgr.exe] ModuleName : C:\WINDOWS\system32\wdfmgr.exe Command Line : C:\WINDOWS\system32\wdfmgr.exe ProcessID : 560 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:25 [vptray.exe] ModuleName : C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe Command Line : "C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe" ProcessID : 568 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 8.1.0.825 ProductVersion : 8.1.0.825 ProductName : Symantec AntiVirus CompanyName : Symantec Corporation FileDescription : Symantec AntiVirus LegalCopyright : Copyright © Symantec Corporation 1991-2003 #:26 [vmconsole.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe" /windowmin ProcessID : 576 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 3.1.00.06230 ProductVersion : 3.1.00.00000 ProductName : VAIO Media Integrated Server CompanyName : Sony Corporation FileDescription : VAIO Media Console InternalName : VMConsole LegalCopyright : Copyright 2002 2003 2004 Sony Corp. OriginalFilename : VMConsole.EXE #:27 [vaioupdt.exe] ModuleName : C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe Command Line : "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary ProcessID : 644 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:28 [switcher.exe] ModuleName : C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe Command Line : "C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe" ProcessID : 660 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 3, 0, 0, 10250 ProductVersion : 3, 0, 0, 10250 ProductName : Wireless Switch Setting Utility CompanyName : Sony Corporation FileDescription : Wireless Switch Setting Utility InternalName : Wireless Switch Setting Utility LegalCopyright : Copyright 2004 Sony Corp. OriginalFilename : Switcher.exe Comments : Wireless Switch Setting Utility #:29 [ssaad.exe] ModuleName : C:\PROGRA~1\sony\SONICS~1\SsAAD.exe Command Line : "C:\PROGRA~1\sony\SONICS~1\SsAAD.exe" ProcessID : 668 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 3.0.00.13241 FileDescription : SonicStage Atrac Hard Disk Monitor InternalName : SonicStage Atrac Hard Disk Monitor LegalCopyright : Copyright 2005 Sony Corporation #:30 [vesmgr.exe] ModuleName : C:\Program Files\Sony\VAIO Event Service\VESMgr.exe Command Line : "C:\Program Files\Sony\VAIO Event Service\VESMgr.exe" ProcessID : 676 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 2.0.00.09300 ProductVersion : 2.0.00 ProductName : VAIO Event Service CompanyName : Sony Corporation FileDescription : VAIO Event Service (Service Module) InternalName : VESMgr.exe LegalCopyright : Copyright 2004,2005 Sony Corp. OriginalFilename : VESMgr.exe #:31 [spmgr.exe] ModuleName : C:\Program Files\Sony\VAIO Power Management\SPMgr.exe Command Line : "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe" ProcessID : 684 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 1.6.0.10190 ProductVersion : 1.6.0 ProductName : Sony Power Management CompanyName : Sony Corporation FileDescription : SPM Module LegalCopyright : © Sony Corporation. All rights reserved. #:32 [shstat.exe] ModuleName : C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE Command Line : "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE ProcessID : 696 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:33 [seeve.exe] ModuleName : C:\WINDOWS\seeve.exe Command Line : "C:\WINDOWS\seeve.exe" ProcessID : 708 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 6.04 ProductVersion : 6.04 ProductName : pop64 CompanyName : Network1 InternalName : seeve OriginalFilename : seeve.exe #:34 [picsvr.exe] ModuleName : C:\WINDOWS\system32\picsvr\picsvr.exe Command Line : "C:\WINDOWS\system32\picsvr\picsvr.exe" ProcessID : 420 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:35 [nsvsvc.exe] ModuleName : C:\WINDOWS\system32\nsvsvc\nsvsvc.exe Command Line : "C:\WINDOWS\system32\nsvsvc\nsvsvc.exe" ProcessID : 752 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 2.17.0000 ProductVersion : 2, 1, 7, 0 #:36 [updaterui.exe] ModuleName : C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe Command Line : "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" ProcessID : 804 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 3.0.0.595 ProductName : McAfee Common Framework CompanyName : Network Associates, Inc. FileDescription : Common User Interface InternalName : UpdaterUI LegalCopyright : Copyright© 2000-2002 Networks Associates Technology, Inc. All Rights Reserved. OriginalFilename : UpdaterUI.exe #:37 [isbmgr.exe] ModuleName : C:\Program Files\Sony\ISB Utility\ISBMgr.exe Command Line : "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" ProcessID : 1072 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:38 [vmisrv.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe" ProcessID : 1196 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:39 [apoint.exe] ModuleName : C:\Program Files\Apoint\Apoint.exe Command Line : "C:\Program Files\Apoint\Apoint.exe" ProcessID : 1508 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal FileVersion : 5.5.7.136 ProductVersion : 5.5.7.136 ProductName : Alps Pointing-device Driver CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver InternalName : Alps Pointing-device Driver LegalCopyright : Copyright © 1999-2003 Alps Electric Co., Ltd. OriginalFilename : Apoint.exe #:40 [vcsw.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe" -RunBySCM ProcessID : 1540 ThreadCreationTime : 6-30-2005 2:32:49 AM BasePriority : Normal #:41 [vzcdbsvc.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe" ProcessID : 1744 ThreadCreationTime : 6-30-2005 2:32:50 AM BasePriority : Normal #:42 [acrotray.exe] ModuleName : C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe Command Line : "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" ProcessID : 1776 ThreadCreationTime : 6-30-2005 2:32:50 AM BasePriority : Normal FileVersion : 6.0.1.2004121400 ProductVersion : 6.0.1.2004121400 ProductName : AcroTray - Adobe Acrobat Distiller helper application. CompanyName : Adobe Systems Inc. FileDescription : AcroTray InternalName : AcroTray LegalCopyright : Copyright 1984-2004 Adobe Systems Incorporated and its licensors. All rights reserved. OriginalFilename : AcroTray.exe #:43 [hpztsb11.exe] ModuleName : C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe Command Line : "C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" ProcessID : 1460 ThreadCreationTime : 6-30-2005 2:32:50 AM BasePriority : Normal FileVersion : 2.327.1.0 ProductVersion : 2.327.1.0 ProductName : HP DeskJet CompanyName : HP LegalCopyright : Copyright © Hewlett-Packard Company 1999-2004 #:44 [hpwuschd2.exe] ModuleName : C:\Program Files\HP\HP Software Update\HPWuSchd2.exe Command Line : "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" ProcessID : 2220 ThreadCreationTime : 6-30-2005 2:32:51 AM BasePriority : Normal FileVersion : 2, 0, 39, 0 ProductVersion : 2, 0, 39, 0 ProductName : Hewlett-Packard hpwuSchd CompanyName : Hewlett-Packard Company FileDescription : hpwuSchd InternalName : hpwuSchd LegalCopyright : Copyright © 2003 OriginalFilename : hpwuSchd2.exe #:45 [vzfw.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Command Line : "C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe" ProcessID : 2280 ThreadCreationTime : 6-30-2005 2:32:51 AM BasePriority : Normal #:46 [hpcmpmgr.exe] ModuleName : C:\Program Files\HP\hpcoretech\hpcmpmgr.exe Command Line : "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" ProcessID : 2408 ThreadCreationTime : 6-30-2005 2:32:51 AM BasePriority : Normal FileVersion : 2.1.1.0 ProductVersion : 2.1.5 ProductName : hp coretech (COmponent REuse TECHnology) CompanyName : Hewlett-Packard Company FileDescription : HP Framework Component Manager Service InternalName : HPComponentManagerService module LegalCopyright : Copyright © Hewlett-Packard. 2002-2004 OriginalFilename : HpCmpMgr.exe #:47 [hphmon06.exe] ModuleName : C:\WINDOWS\system32\hphmon06.exe Command Line : "C:\WINDOWS\system32\hphmon06.exe" ProcessID : 2524 ThreadCreationTime : 6-30-2005 2:32:51 AM BasePriority : Normal FileVersion : 6,0,72 ProductVersion : 6,0,72 ProductName : HP Photosmart CompanyName : Hewlett-Packard FileDescription : HPHmon06 InternalName : HPHmon06 LegalCopyright : Copyright © 2004 OriginalFilename : HPHmon06.exe #:48 [qttask.exe] ModuleName : C:\Program Files\QuickTime\qttask.exe Command Line : "C:\Program Files\QuickTime\qttask.exe" -atboottime ProcessID : 2568 ThreadCreationTime : 6-30-2005 2:32:51 AM BasePriority : Normal FileVersion : 6.4 ProductVersion : QuickTime 6.4 ProductName : QuickTime CompanyName : Apple Computer, Inc. InternalName : QuickTime Task LegalCopyright : © Apple Computer, Inc. 2001-2003 OriginalFilename : QTTask.exe #:49 [msmsgs.exe] ModuleName : C:\Program Files\Messenger\msmsgs.exe Command Line : "C:\Program Files\Messenger\msmsgs.exe" /background ProcessID : 2932 ThreadCreationTime : 6-30-2005 2:32:52 AM BasePriority : Normal FileVersion : 4.7.3001 ProductVersion : Version 4.7.3001 ProductName : Messenger CompanyName : Microsoft Corporation FileDescription : Windows Messenger InternalName : msmsgs LegalCopyright : Copyright © Microsoft Corporation 2004 LegalTrademarks : Microsoft® is a registered trademark of Microsoft Corporation in the U.S. and/or other countries. OriginalFilename : msmsgs.exe #:50 [sv_httpd.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP" ProcessID : 3040 ThreadCreationTime : 6-30-2005 2:32:52 AM BasePriority : Normal FileVersion : 3.0.00.06160 ProductVersion : 3.0.00.13260 ProductName : SV_Httpd.exe CompanyName : Sony Corporation FileDescription : Sony HTTP Server InternalName : SV_Httpd LegalCopyright : Copyright 2002, 2003, 2004 Sony Corp. OriginalFilename : SV_Httpd.exe #:51 [ctfmon.exe] ModuleName : C:\WINDOWS\system32\ctfmon.exe Command Line : "C:\WINDOWS\system32\ctfmon.exe" ProcessID : 3084 ThreadCreationTime : 6-30-2005 2:32:53 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : CTF Loader InternalName : CTFMON LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : CTFMON.EXE #:52 [apntex.exe] ModuleName : C:\Program Files\Apoint\Apntex.exe Command Line : "Apntex.exe" ProcessID : 3108 ThreadCreationTime : 6-30-2005 2:32:53 AM BasePriority : Normal FileVersion : 5.0.1.15 ProductVersion : 5.0.1.15 ProductName : Alps Pointing-device Driver for Windows NT/2000/XP CompanyName : Alps Electric Co., Ltd. FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP InternalName : Alps Pointing-device Driver for Windows NT/2000/XP LegalCopyright : Copyright © 1998-2003 Alps Electric Co., Ltd. OriginalFilename : ApntEx.exe #:53 [upnpframework.exe] ModuleName : C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe Command Line : "C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe" ProcessID : 3120 ThreadCreationTime : 6-30-2005 2:32:53 AM BasePriority : Normal FileVersion : 6.0.00.06220 ProductVersion : 6.0.00.06220 ProductName : UPnPFramework.exe CompanyName : Sony Corporation FileDescription : Sony UPnP Framework InternalName : UPnPFramework LegalCopyright : Copyright 2002,2003,2004 Sony Corp. OriginalFilename : UPnPFramework.exe #:54 [acrobat_sl.exe] ModuleName : C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe Command Line : "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\acrobat_sl.exe" ProcessID : 3156 ThreadCreationTime : 6-30-2005 2:32:53 AM BasePriority : Normal FileVersion : 7.0.0.0 ProductVersion : 7.0.0.0 ProductName : Adobe Acrobat CompanyName : Adobe Systems Incorporated FileDescription : Adobe Acrobat SpeedLauncher LegalCopyright : Copyright Adobe Systems Incorporated 2004 OriginalFilename : AcroSpeedLaunch.exe #:55 [ssscsisv.exe] ModuleName : C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe Command Line : "C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe" ProcessID : 3296 ThreadCreationTime : 6-30-2005 2:32:54 AM BasePriority : Normal FileVersion : 3.0.00.13241 ProductVersion : 3.0.00 ProductName : SonicStage CompanyName : Sony Corporation FileDescription : SonicStage Scsi I/F Server InternalName : SSScsiSV LegalCopyright : Copyright 2005 Sony Corporation OriginalFilename : SSScsiSV.EXE #:56 [wscntfy.exe] ModuleName : C:\WINDOWS\system32\wscntfy.exe Command Line : C:\WINDOWS\system32\wscntfy.exe ProcessID : 3948 ThreadCreationTime : 6-30-2005 2:32:56 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows Security Center Notification App InternalName : wscntfy.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wscntfy.exe #:57 [wmiprvse.exe] ModuleName : C:\WINDOWS\system32\wbem\wmiprvse.exe Command Line : C:\WINDOWS\system32\wbem\wmiprvse.exe -Embedding ProcessID : 232 ThreadCreationTime : 6-30-2005 2:32:57 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:58 [sideact.exe] ModuleName : C:\Program Files\ACT\SideACT.exe Command Line : "C:\Program Files\ACT\SideACT.exe" /s ProcessID : 616 ThreadCreationTime : 6-30-2005 2:32:57 AM BasePriority : Normal #:59 [hpzipm12.exe] ModuleName : C:\WINDOWS\system32\HPZipm12.exe Command Line : C:\WINDOWS\system32\HPZipm12.exe ProcessID : 1768 ThreadCreationTime : 6-30-2005 2:32:58 AM BasePriority : Normal FileVersion : 8, 0, 0, 0 ProductVersion : 8, 0, 0, 0 ProductName : HP PML CompanyName : HP FileDescription : PML Driver InternalName : PmlDrv LegalCopyright : Copyright © 1998, 1999 Hewlett-Packard Company OriginalFilename : PmlDrv.exe #:60 [alg.exe] ModuleName : C:\WINDOWS\System32\alg.exe Command Line : C:\WINDOWS\System32\alg.exe ProcessID : 2300 ThreadCreationTime : 6-30-2005 2:32:58 AM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:61 [hpqgalry.exe] ModuleName : C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe Command Line : "C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe" -s ProcessID : 2440 ThreadCreationTime : 6-30-2005 2:32:59 AM BasePriority : Normal #:62 [ad-aware.exe] ModuleName : C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe Command Line : "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" ProcessID : 1556 ThreadCreationTime : 6-30-2005 2:33:34 AM BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved #:63 [wuauclt.exe] ModuleName : C:\WINDOWS\system32\wuauclt.exe Command Line : "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[48c]SUSDS8e170ccf2c257646aacb1c41a96160a4 ProcessID : 2860 ThreadCreationTime : 6-30-2005 2:33:37 AM BasePriority : Normal FileVersion : 5.8.0.2469 built by: lab01_n(wmbla) ProductVersion : 5.8.0.2469 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Automatic Updates InternalName : wuauclt.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : wuauclt.exe Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 0 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» VX2 Object Recognized! Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3n5trMsgSDisp VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky1S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky2S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky3S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUs3t5icky4S VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC1o3d5eOfSFinalAd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3i5m7eOfSFinalAd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUD3s5tSSEnd VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AU3N5a7tionSCode VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUP3D5om VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSCheckSIn VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSMots VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUM3o5deSSync VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSCab VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSEx VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3n5ProgSLstest VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUB3D5om VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUE3v5nt VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSBath VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUT3h5rshSysSInf VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUL3n5Title VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3u5rrentSMode VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUC3n5tFyl VX2 Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_USERS Object : S-1-5-21-3550750962-3212643581-3147056831-1006\software\aurora Value : AUI3g5noreS Windows Object Recognized! Type : RegData Data : explorer.exe c:\windows\nail.exe TAC Rating : 3 Category : Vulnerability Comment : Shell Possibly Compromised Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\windows nt\currentversion\winlogon Value : Shell Data : explorer.exe c:\windows\nail.exe Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 26 Objects found so far: 26 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Trusted zone presumably compromised : media-motor.net Possible Browser Hijack attempt Object Recognized! Type : Regkey Data : TAC Rating : 3 Category : Vulnerability Comment : Trusted zone presumably compromised : media-motor.net Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\media-motor.net Trusted zone presumably compromised : popuppers.com Possible Browser Hijack attempt Object Recognized! Type : Regkey Data : TAC Rating : 3 Category : Vulnerability Comment : Trusted zone presumably compromised : popuppers.com Rootkey : HKEY_CURRENT_USER Object : Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\popuppers.com Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 2 Objects found so far: 28 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 28 Deep scanning and examining files (C:) »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 28 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 28 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 28 9:41:22 PM Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:06:59.813 Objects scanned:119904 Objects identified:28 Objects ignored:0 New critical objects:28 |
|
|
Jun 30 2005, 06:19 AM
Post
#8
|
|
![]() Visiting Staff Posts: 4,746 From: Finland OS: XP Home - SP2 |
Hello all.
AAW has no power for this infection you have.. Wait for an mod to come and move this topic to Malware removal forum. You have to download HiJackThis 1.99.1 and install it. Install it to a proper location such as C:\HJT, and do not run it from temporary location because it cannot then create backups. Once you have downloaded & installed it, launch it and hit "Do a full system scan and save the logfile". When the scan has finished, a notepad file will open with a log. Copy & paste all of it's content to your next reply to this topic. When this topic has been moved to Malware removal, someone from our trained HJT staff will come and help you with your problems. Do not fix anything yet! - Rawe |
|
|
Jun 30 2005, 06:46 AM
Post
#9
|
|
![]() SuperStar Posts: 11,418 From: In the gym OS: xp home, xp pro |
Please follow Rawe's helpful advice and post a new log in this thread. This has now been moved to the malware infection, where a staff member will look at it.
|
|
|
Jun 30 2005, 09:55 AM
Post
#10
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
I am a bit concerned now. Since I followed the directions of the Andy, my computer is very slow. I just hope that it is this malware prob that is causing it and not something that I did yesterday. This is the HijackThis log, thank you again for help in this matter, I truly appreciate it. Have a great day!
Thanks again, Tarina Logfile of HijackThis v1.99.1 Scan saved at 10:47:13 AM, on 6/30/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe C:\Program Files\Executive Software\Diskeeper\DkService.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\PROGRA~1\sony\SONICS~1\SsAAD.exe C:\Program Files\Sony\VAIO Power Management\SPMgr.exe C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE C:\WINDOWS\system32\picsvr\picsvr.exe C:\WINDOWS\system32\nsvsvc\nsvsvc.exe C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe C:\Program Files\Sony\VAIO Event Service\VESMgr.exe C:\Program Files\HP\HP Software Update\HPWuSchd2.exe C:\Program Files\HP\hpcoretech\hpcmpmgr.exe C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe C:\WINDOWS\system32\hphmon06.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe C:\Program Files\Messenger\msmsgs.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe C:\Program Files\ACT\SideACT.exe C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\HPZipm12.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\PeDevice\PeDev.exe C:\WINDOWS\system32\taskmgr.exe C:\DOCUME~1\LEEMEN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [VMConsole.exe] C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe /windowmin O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe O4 - Global Startup: SideACT!.lnk = C:\Program Files\ACT\SideACT.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: MSN Messenger - {978ac263-6169-4969-9ca8-dc16fe0f45aa} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: MSN Messenger - {978ac263-6169-4969-9ca8-dc16fe0f45aa} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing) O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing) O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing) O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing) O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe |
|
|
Jun 30 2005, 07:31 PM
Post
#11
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Hi tarina
Need you to do a few things please Create a folder on the C: drive called C:\HJT. You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it HJT Please move HJT into this new folder please Next Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: http://www.dknoppix.com/cgi-bin/download.cgi?Nailfix Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode. For additional help in booting into Safe Mode, see the following site: http://www.pchell.com/support/safemode.shtml Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal. Then please run Ewido, and run a full scan. Save the logfile from the scan. Next please run HijackThis, click Scan, and check: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe O4 - HKLM\..\Run: [picsvr] C:\WINDOWS\system32\picsvr\picsvr.exe O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.popuppers.com O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab Close all open windows except for HijackThis and click Fix Checked. Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan. |
|
|
Jul 1 2005, 06:19 PM
Post
#12
|
|
|
New Member ![]() Posts: 6 OS: windows xp |
It seems like there has been some progress, but the computer is still really slow. It took me hours to do this because of that. So, on that note, here is the HiJackThis log:
Logfile of HijackThis v1.99.1 Scan saved at 5:44:05 PM, on 7/1/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\explorer.exe C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.sony.com/vaiopeople F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe O4 - HKLM\..\Run: [VMConsole.exe] C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VMConsole.exe /windowmin O4 - HKLM\..\Run: [VAIOSurvey] c:\program files\sony\vaio survey\surveysa.exe O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary O4 - HKLM\..\Run: [VAIO Recovery] C:\WINDOWS\Sonysys\VAIO Recovery\PartSeal.exe O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\sony\SONICS~1\SsAAD.exe O4 - HKLM\..\Run: [SonyPowerCfg] C:\Program Files\Sony\VAIO Power Management\SPMgr.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\digital imaging\bin\hpqtra08.exe O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\digital imaging\bin\hpqthb08.exe O4 - Global Startup: SideACT!.lnk = C:\Program Files\ACT\SideACT.exe O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no file) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: MSN Messenger - {978ac263-6169-4969-9ca8-dc16fe0f45aa} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra 'Tools' menuitem: MSN Messenger - {978ac263-6169-4969-9ca8-dc16fe0f45aa} - C:\WINDOWS\system32\shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540013} (CInstall Class) - http://adserver.sharewareonline.com/adserver/Install.cab O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: VESWinlogon - C:\WINDOWS\SYSTEM32\VESWinlogon.dll O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper\DkService.exe O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe O23 - Service: VAIO Entertainment Aggregation and Control Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment\VzRs\VzRs.exe O23 - Service: VAIO Entertainment Task Scheduler - Sony Corporation - C:\Program Files\Sony\vaio entertainment\VzTaskScheduler.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-IntegratedServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\IntegratedServer\HTTP (file missing) O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe" /Service=VAIOMediaPlatform-Mobile-Gateway /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Addons\Packages\Mobile\Gateway" /DisplayName="VAIO Media Gateway Server (file missing) O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing) O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing) O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe Here is the Ewido scan: ewido security suite - Scan report --------------------------------------------------------- + Created on: 5:43:30 PM, 7/1/2005 + Report-Checksum: 1A9479A3 + Date of database: 7/1/2005 + Version of scan engine: v3.0 + Duration: 61 min + Scanned Files: 64245 + Speed: 17.46 Files/Second + Infected files: 9 + Removed files: 9 + Files put in quarantine: 9 + Files that could not be opened: 0 + Files that could not be cleaned: 0 + Binder: Yes + Crypter: Yes + Archives: Yes + Scanned items: C:\ + Scan result: C:\Documents and Settings\Lee Mendelsohn\Cookies\lee mendelsohn@atdmt[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Documents and Settings\Lee Mendelsohn\Cookies\lee mendelsohn@fastclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup C:\Documents and Settings\Lee Mendelsohn\Local Settings\Temp\XOL\aurareco.exe -> Spyware.BetterInternet -> Cleaned with backup C:\WINDOWS\Downloaded Program Files\m67m.ocx -> Spyware.MediaMotor.a -> Cleaned with backup C:\WINDOWS\jlidhdldwk.exe -> Spyware.BetterInternet -> Cleaned with backup C:\WINDOWS\systb.dll -> Spyware.ImiBar.d -> Cleaned with backup C:\WINDOWS\system32\dcaeyqw.exe -> Spyware.BetterInternet -> Cleaned with backup C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c -> Cleaned with backup C:\WINDOWS\wupdt.exe -> TrojanDownloader.Intexp.c -> Cleaned with backup ::Report End Thanks again for all your help! Tarina |
|
|
Jul 4 2005, 11:06 AM
Post
#13
|
|
![]() Malware Expert Posts: 18,682 From: Boston Ma. OS: XP Pro,ME, 98 |
Hi again Tarina, sorry for the delay in reply.
Lets run through this one more time please Please download the trial version of Ewido Security Suite here: http://www.ewido.net/en/download/ Install it, and update the definitions to the newest files. Do NOT run a scan yet. Please download Nailfix from here: http://www.noidea.us/easyfile/file.php?dow...050515010747824 Unzip it to the desktop but please do NOT run it yet. Next, please reboot your computer in Safe Mode by doing the following: 1) Restart your computer 2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3) Instead of Windows loading as normal, a menu should appear 4) Select the first option, to run Windows in Safe Mode. For additional help in booting into Safe Mode, see the following site: http://www.pchell.com/support/safemode.shtml Once in Safe Mode, please double-click on Nailfix.cmd. Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal. Then please run Ewido, and run a full scan. Save the logfile from the scan. Next please run HijackThis, click Scan, and check: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q= F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing) O2 - BHO: PEDEV_IEListener Class - {E1412445-4FF8-410e-8D24-F2CF86B171A4} - C:\Program Files\PeDevice\PeDev.dll O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file) O4 - HKLM\..\Run: [seeve] C:\WINDOWS\seeve.exe O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\system32\nsvsvc\nsvsvc.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540006} (CInstall Class) - http://www.errorguard.com/installation/Install.cab Click on Fix Checked when finished and exit HijackThis. Close all open windows except for HijackThis and click Fix Checked. Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
11 / 779 | 21st June 2005 - 11:46 PM y2kfroguy started - last by loophole |
|||||
![]() |
10 / 831 | 2nd July 2005 - 11:15 AM valiegurl started - last by therock247uk |
|||||
![]() |
0 / 0 | 30th June 2005 - 06:46 AM tarina started - last by coachwife6 |
|||||
![]() |
6 / 1,568 | 14th August 2005 - 11:41 AM jamesl started - last by Buckeye_Sam |
|||||
|
Time is now: 7th November 2009 - 11:03 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising