Incident Status Location
Virus:Bck/Agent.FY Disinfected Operating system
Adware:Adware/VirusBurst Not disinfected C:\WINDOWS\System32\gtpbx.dll
Spyware:spyware/linkreplacer Not disinfected c:\windows\system32\lmf32v.dll
Adware:adware/midaddle Not disinfected c:\windows\system32\PreUninstall.exe
Adware:adware/isearch Not disinfected Windows Registry
Adware:adware/favoriteman Not disinfected Windows Registry
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.com.com/]
Spyware:Cookie/VirusBurst Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[www.virusburst.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\William Heagy\Application Data\Mozilla\Firefox\Profiles\r1m2hik8.default\cookies.txt[.gostats.com/]
Virus:W32/Virutas.B Not disinfected C:\Documents and Settings\William Heagy\Desktop\data.rar[client.exe]
Virus:W32/Virutas.B Not disinfected C:\Documents and Settings\William Heagy\Local Settings\Temporary Internet Files\Content.IE5\JHQ0V75U\data[1].rar[client.exe]
Adware:Adware/PCodec Not disinfected C:\Program Files\PCODEC\isamini.exe
Adware:Adware/PCodec Not disinfected C:\Program Files\PCODEC\isamonitor.exe
Adware:Adware/PCodec Not disinfected C:\RECYCLER\S-1-5-21-73586283-839522115-1060284298-1003\Dc5\backup-20060905-221006-413.dll
Adware:Adware/PCodec Not disinfected C:\RECYCLER\S-1-5-21-73586283-839522115-1060284298-1003\Dc5\backup-20060905-221026-872.dll
Adware:Adware/PCodec Not disinfected C:\RECYCLER\S-1-5-21-73586283-839522115-1060284298-1003\Dc5\backup-20060911-171512-609.dll
Adware:Adware/NetPals Not disinfected C:\RECYCLER\S-1-5-21-73586283-839522115-1060284298-1003\Dc5\backup-20061009-062255-742.inf
Adware:Adware/ISearch Not disinfected C:\WINDOWS\HLInstaller6b.exe
Virus:Trj/LowZones.SM Disinfected C:\WINDOWS\system32\bikini.exe
Adware:Adware/ISearch Not disinfected C:\WINDOWS\system32\HyperLinker6.exe
Adware:Adware/nCase Not disinfected C:\WINDOWS\system32\nC5594Om3.dll
Logfile of HijackThis v1.99.1
Scan saved at 10:47:41 AM, on 10/14/2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\D-Link\Wireless G WDA-1320\AirGCFG.exe
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\William Heagy\Desktop\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [D-Link Wireless G WDA-1320] C:\Program Files\D-Link\Wireless G WDA-1320\AirGCFG.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Steam] C:\Program Files\Steam\Steam.exe -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O18 - Filter: text/html - (no CLSID) - (no file)
O21 - SSODL: died - {7fa55359-7223-410f-bc82-efb3e3ded07f} - C:\WINDOWS\System32\gtpbx.dll
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe