Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Torjan.Elitebar, Hacktool.Rootkit, Downloader.Troj [CLOSED]


  • This topic is locked This topic is locked

#16
Anker137

Anker137

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, October 19, 2005 17:01:11
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 19/10/2005
Kaspersky Anti-Virus database records: 145694
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 81914
Number of viruses found: 17
Number of infected objects: 131
Number of suspicious objects: 0
Duration of the scan process: 11860 sec

Infected Object Name - Virus Name
C:\!KillBox\93_app13.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\!KillBox\drttia.exe Infected: Trojan.Win32.Pakes
C:\!KillBox\eoaaa.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\!KillBox\fksssss.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\!KillBox\jacksunset.exe/WISE0021.BIN Infected: Trojan-Dropper.Win32.Small.jh
C:\!KillBox\jacksunset.exe Infected: Trojan-Dropper.Win32.Small.jh
C:\!KillBox\krmmw.dll Infected: Trojan-Downloader.Win32.Qoologic.ak
C:\!KillBox\ltccoic.dll Infected: Trojan-Downloader.Win32.Qoologic.af
C:\!KillBox\mmxdoubleexe.exe Infected: Trojan-Downloader.Win32.VB.jl
C:\!KillBox\s4ppsl.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\!KillBox\ServUDaemon.ini Infected: Backdoor.Win32.ServU-based
C:\!KillBox\ssk3b5doublemedia.exe/data0005 Infected: Trojan-Dropper.Win32.Small.qn
C:\!KillBox\ssk3b5doublemedia.exe Infected: Trojan-Dropper.Win32.Small.qn
C:\!KillBox\vgactl.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\!KillBox\wuauclt.dll Infected: Trojan-Downloader.Win32.Qoologic.ae
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02B00000.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\02B00001.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\032C0000.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\03300000.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\08F80000.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\09180000.VBN Infected: Trojan.Win32.EliteBar.f
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\rpaa.exe Infected: Trojan.Win32.Pakes
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP186\A0046041.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP186\A0046084.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP187\A0046112.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP187\A0046119.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP188\A0046152.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP189\A0046208.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP189\A0046219.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP190\A0046323.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP190\A0046336.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP190\A0046356.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP191\A0046415.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP192\A0046445.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP193\A0047081.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP195\A0047268.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP196\A0047324.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP197\A0047356.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP200\A0047606.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP200\A0047628.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP202\A0048628.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP208\A0048878.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP211\A0049272.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP218\A0049511.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP218\A0049530.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP220\A0050128.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP222\A0050328.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP228\A0051038.dll Infected: Trojan.Win32.EliteBar.d
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP228\A0051039.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP228\A0051045.dll Infected: Trojan.Win32.EliteBar.d
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP228\A0051094.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP228\A0051095.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP230\A0051147.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP230\A0051148.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP230\A0051160.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP230\A0051161.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP231\A0051235.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP231\A0051236.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP232\A0052219.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP232\A0052220.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP232\A0053218.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP232\A0053219.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0053273.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0053274.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0054261.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0054262.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0054291.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0055261.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0055262.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056261.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056262.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056277.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056278.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056313.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056314.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056326.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056327.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056344.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056345.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056369.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0056371.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0057370.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0057371.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0057545.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP233\A0057546.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0058510.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0058511.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0059510.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0059511.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0060510.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP234\A0060511.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061510.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061511.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061520.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061522.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061525.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061536.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061551.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061552.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061581.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061582.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061601.exe Infected: Trojan-Downloader.Win32.VB.hw
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061602.exe Infected: Trojan-Downloader.Win32.Dyfuca.ei
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061604.exe Infected: Trojan-Downloader.Win32.Agent.qg
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061605.exe Infected: Trojan-Downloader.Win32.Agent.vp
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061607.exe Infected: Trojan-Dropper.Win32.Small.qn
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061668.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061669.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061686.exe/data0005 Infected: Trojan-Dropper.Win32.Small.qn
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061686.exe Infected: Trojan-Dropper.Win32.Small.qn
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061687.exe Infected: Trojan-Dropper.Win32.Agent.xw
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061688.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061689.dll Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061690.ini Infected: Backdoor.Win32.ServU-based
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061691.exe Infected: Trojan-Downloader.Win32.VB.jl
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061692.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061693.dll Infected: Trojan-Downloader.Win32.Qoologic.ae
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061699.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP235\A0061700.exe Infected: Trojan-Downloader.Win32.Qoologic.ac
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061779.exe Infected: Trojan.Win32.Pakes
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061789.exe Infected: Trojan.Win32.Pakes
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061790.dll Infected: Trojan-Downloader.Win32.Qoologic.af
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061791.dll Infected: Trojan-Downloader.Win32.Qoologic.ak
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061801.dll Infected: Trojan-Downloader.Win32.Qoologic.ae
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061805.dll Infected: Trojan-Downloader.Win32.Qoologic.ak
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061806.dll Infected: Trojan-Downloader.Win32.Qoologic.af
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061809.dll Infected: Trojan-Downloader.Win32.Qoologic.ae
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061811.cpl Infected: Trojan-Downloader.Win32.Qoologic.ad
C:\System Volume Information\_restore{68DCCD3E-2073-4915-A5DC-A445A55876AD}\RP236\A0061813.exe Infected: Trojan.Win32.Pakes
C:\WINDOWS\system32\draamba.exe Infected: Trojan.Win32.Pakes
C:\WINDOWS\system32\wbuuk.dat Infected: Trojan-Downloader.Win32.Qoologic.ac

Scan process completed.

Logfile of HijackThis v1.99.1
Scan saved at 11:48:11 PM, on 10/19/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\QW5ldGEgS3J1awAA\command.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\carpserv.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\HPQ\One-Touch\OneTouch.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\PROGRA~1\COMMON~1\AOL\110790~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\COMMON~1\AOL\110790~1\EE\AOLServiceHost.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Gadu-Gadu\gg.exe
C:\Program Files\AIM\aim.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.newpaltz.edu/
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [QT4HPOT] C:\Program Files\HPQ\One-Touch\OneTouch.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1107909060\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CMSystem] "C:\Program Files\CMSystem\CMSystem.exe"
O4 - Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - c:\Program Files\Microsoft Money\System\mnyside.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .m14: C:\Program Files\Modern Age Books\Vbook\NPVbok32.dll
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O14 - IERESET.INF: START_PAGE_URL=http://qus8l.hpwis.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.popuppers.com
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefend...can8/oscan8.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akama...meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093393851460
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe (file missing)
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\QW5ldGEgS3J1awAA\command.exe
O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: FireDaemon Service: IRoffer (IRoffer) - Sublime Solutions Pty Ltd - C:\WINDOWS\System32\Macromed\fdaemon\FireDaemon.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: FireDaemon Service: ServU (ServU) - Sublime Solutions Pty Ltd - C:\WINDOWS\System32\Macromed\fdaemon\FireDaemon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
  • 0

Advertisements


#17
skate_punk_21

skate_punk_21

    Malware Removal Expert

  • Retired Staff
  • 1,049 posts
delete this folder: C:\!killbox

empty the CONTENTS of this folder: C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus Corporate Edition\7.5\Quarantine\

and delete these Files: C:\WINDOWS\system32\draamba.exe
C:\WINDOWS\system32\wbuuk.dat


Let me know if either of these are troublesome, then i will post preventative measures
  • 0

#18
Anker137

Anker137

    New Member

  • Topic Starter
  • Member
  • Pip
  • 9 posts
It's been a while and so far no problems :tazz: Thank you so much.
  • 0

#19
skate_punk_21

skate_punk_21

    Malware Removal Expert

  • Retired Staff
  • 1,049 posts
Congratulations Your Log is Clean!!

If you are still having trouble, please dont continue with these instructions just yet. LET ME KNOW!

Otherwise, we have a few clean up items to deal with.

1. System Restore
Now that we know your system is clean, we want to purge any potentially infected restore points. To do that, complete the following:

Turn off System Restore by Clicking Start > right-click My Computer and then click Properties. Click the System Restore tab > Check "Turn off System Restore" or "Turn off System Restore on all drives". Click Apply. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. Click OK.

To re-enable this function - simply uncheck this same box, and click "apply" and "ok"


2. Reset Hidden Files & Folders
Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is UNchecked. Also make sure that the System Files and Folders are invisible. CHECK the Hide protected operating system files option.


Also Consider...
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
You should also have a good firewall. Here are 3 free ones available for personal use:
How is she running now? Any further problems? If not, Good work, and Happy Computing!

Please reply once more so we know you have read these measures.
  • 0

#20
skate_punk_21

skate_punk_21

    Malware Removal Expert

  • Retired Staff
  • 1,049 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP