Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Infected with scvhost.exe and maybe more


  • Please log in to reply

#1
regmcube

regmcube

    New Member

  • Member
  • Pip
  • 3 posts
I followed all of the instructions of the "removing malware" post.

In the end, I think that the only thing I'm still infected with is "scvhost.exe" and that is my main concern, having read about it online and seeing how difficult it is to remove. But perhaps there is more malware that I haven't detected? Someone please help! I appreciate it very much!

Here is a summary of what happened:

First I made sure everything was enabled in my msconfig startup.

Then:

1) AVG Anti-Spyware found a whole bunch of spyware (while I was in Safemode)

2) SUPERAntiSpyware Home Edition found NO spyware

3) Panda ActiveScan online found one virus and one spyware, but it only cleaned the virus.

After this, i went in and deleted where the one spyware was detected.

4) My Symantec Antivirus scan showed no infected files (however, almost every time i start my computer, it pops up saying that scvhost.exe has infected my computer and it cleans it, but it keeps coming back)

Then I went into regedit and search for "scvhost.exe" and deleted all the instances of scvhost.exe (being careful NOT to delete svchost.exe) from my registry

5) I then updated my Windows

6) Then I ran HJT



Here is a list of all my logs/reports, in order of the above:


-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
----------------------------------------------AVG Anti-Spyware Log-----------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:51:28 PM 7/28/2007

+ Scan result:



HKLM\SOFTWARE\Classes\WR -> Adware.Generic : Cleaned with backup (quarantined).
:mozilla.250:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.251:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.111:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.113:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.24:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.25:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.26:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.114:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.115:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.116:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.117:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.118:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.119:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.120:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.182:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.183:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.184:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.185:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.187:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.214:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.54:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.213:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.26:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.27:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.28:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.205:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.206:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.207:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.208:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.209:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.210:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.171:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.85:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Com : Cleaned.
:mozilla.41:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.280:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.281:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.282:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.242:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.267:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.84:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.85:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.86:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.87:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.88:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.89:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.233:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.234:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.272:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.273:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.267:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.268:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.269:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.223:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.243:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.244:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.129:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.130:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.42:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.43:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.44:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.45:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.47:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.48:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.86:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.88:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.89:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.90:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.217:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.218:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.219:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.220:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.221:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.222:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.137:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.138:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.140:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.141:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.252:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.136:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.139:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.214:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.216:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.123:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.124:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.125:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.126:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.127:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.49:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.50:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.51:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.52:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.53:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.91:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.288:C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.19:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.20:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.21:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.22:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.23:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.24:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.65:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.66:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.67:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.68:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.69:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.70:C:\Documents and Settings\Dan\Application Data\Mozilla\Firefox\Profiles\bhlboger.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.


::Report end


-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-------------------------------------Super Anti-Spyware Home Edition-------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------

SUPERAntiSpyware Scan Log
Generated 07/28/2007 at 11:04 PM

Application Version : 3.6.1000

Core Rules Database Version : 3275
Trace Rules Database Version: 1286

Scan type : Complete Scan
Total Scan Time : 04:54:44

Memory items scanned : 610
Memory threats detected : 0
Registry items scanned : 5753
Registry threats detected : 0
File items scanned : 74270
File threats detected : 0



-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
------------------------------------------Panda Free ActiveScan Online-------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------


Incident Status Location

Virus:W32/Gaobot.PTM.worm Disinfected Operating system


Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Trey\Application Data\Mozilla\Firefox\Profiles\pzngk79g.default\cookies.txt[.adultfriendfinder.com/]



-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------Symantec AntiVirus-------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------

0 infections found

-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------HiJackThis------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------

Logfile of HijackThis
Scan saved at 2:01:01 PM, on 7/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\BeSecure 2005\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\BeSecure 2005\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BeSecure 2005\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\BeSecure 2005\Symantec Client Firewall\SymSPort.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\BESECU~1\SYMANT~2\VPTray.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\ImageStudio\LogiTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\SBC LightSpeed Self Support Tool\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Dan\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\BESECU~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCLIG~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC LightSpeed Self Support Tool\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Office Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1136757564062
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicr...scan/as4web.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Unknown owner - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\BeSecure 2005\Symantec AntiVirus\DefWatch.exe
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\BeSecure 2005\Symantec Client Firewall\ISSVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\BeSecure 2005\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\BeSecure 2005\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\BeSecure 2005\Symantec Client Firewall\SymSPort.exe

Edited by admin, 16 September 2009 - 08:38 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP