View Single Post
Old 10-17-2005, 08:53 AM   #3 (permalink)
cee
Registered User
 
Join Date: Oct 2005
Posts: 5
OS: Win XP Pro


Thank you Horse! Here's are the reports, ActiveScan followed by HijackThis Analyzer:

* * * * * Active Scan Report * * * * *

Incident Status Location

Adware:Adware/Transponder No disinfected C:\WINDOWS\inf\SET8.tmp
Adware:Adware/ImGiant No disinfected C:\WINDOWS\myurlff.exe
Adware:Adware/Transponder No disinfected C:\WINDOWS\cmqqnf.exe
Spyware:Spyware/Media-motor No disinfected C:\WINDOWS\unstall.exe
Possible Virus. No disinfected C:\Documents and Settings\eric\Local Settings\Temporary Internet Files\Content.IE5\CXABCX2V\PIC00010[1].com
Adware:Adware/Maxifiles No disinfected C:\Documents and Settings\eric\Local Settings\Temporary Internet Files\Content.IE5\IF6HY78F\maxifilesdns[1].zip[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\Documents and Settings\eric\Local Settings\Temporary Internet Files\Content.IE5\IF6HY78F\maxifilesdns[1].zip[cwebpage.dll]
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\3UG2833D\init[1].js
Adware:Adware/WUpd No disinfected C:\Documents and Settings\Emily\Local Settings\Temporary Internet Files\Content.IE5\0XIB45IF\bannerads[1].htm
Adware:adware/maxifiles No disinfected C:\Program Files\Common Files\system32.dll
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\system32.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\Program Files\Common Files\system32.dll[cwebpage.dll]
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059911.dll
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059912.exe
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059913.exe
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059914.dll
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059917.dll
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059918.dll
Adware:Adware/Prositefinder No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP156\A0059920.exe
Adware:Adware/WUpd No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP157\A0059989.exe
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP159\A0060076.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP159\A0060076.dll[cwebpage.dll]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP159\A0060078.dll
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP162\A0061525.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP162\A0061525.dll[cwebpage.dll]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP162\A0061529.dll
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP165\A0061622.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP165\A0061622.dll[cwebpage.dll]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP165\A0061623.dll
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP168\A0061715.dll[gui.exe]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP168\A0061715.dll[cwebpage.dll]
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP168\A0061717.DLL
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP168\A0061724.exe
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP168\A0061725.exe
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP170\A0062228.exe
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP170\A0062229.exe
Adware:Adware/Maxifiles No disinfected C:\System Volume Information\_restore{E7A9DF2A-304A-435D-B843-70EA21DECFE5}\RP171\A0062292.dll
Adware:Adware/Maxifiles No disinfected D:\Program Files\Microsoft AntiSpyware\Quarantine\0681AFB3-AEE3-4550-95DF-B6362A\18094883-81BF-43A2-9445-344ED7
Adware:Adware/Maxifiles No disinfected D:\Program Files\Microsoft AntiSpyware\Quarantine\0681AFB3-AEE3-4550-95DF-B6362A\566F0132-291C-4F31-B11D-447D72
Adware:Adware/Maxifiles No disinfected D:\Program Files\Microsoft AntiSpyware\Quarantine\0681AFB3-AEE3-4550-95DF-B6362A\A08F5E14-4110-46AD-93D0-BC5E4E
Adware:Adware/WUpd No disinfected D:\Program Files\Microsoft AntiSpyware\Quarantine\886FF516-F0B1-4C83-B183-6C17D9\4983B341-4349-4AEC-B5B4-CD1F99
Spyware:Spyware/Media-motor No disinfected D:\Program Files\Microsoft AntiSpyware\DeactivatedItems\30E540CE-7904-4976-B682-3094E9.asq
Virus:W32/Sobig.E Disinfected Personal Folders\Inbox\Re: Movie\your_details.zip[details.pif]
Virus:Trj/Mitglieder.EW Disinfected Personal Folders\Deleted Items\price.zip[text.exe]



* * * * * HijackThis Analyzer Report * * * * *

====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 9/28/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 10:49:58 AM, on 10/17/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
D:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
D:\PROGRA~1\AVGFRE~1\avgamsvr.exe
D:\PROGRA~1\AVGFRE~1\avgupsvc.exe
D:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
D:\Program Files\War-ftpd\war-ftpd.exe
D:\Program Files\Microsoft AntiSpyware\gcasServ.exe
D:\PROGRA~1\AVGFRE~1\avgcc.exe
D:\Program Files\iTunes\iTunesHelper.exe
D:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
D:\PROGRA~1\POP-UP~1\PSFREE.EXE
D:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
D:\Program Files\Musicmatch\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\logon.scr
C:\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - D:\Program Files\SnagIt\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [gcasServ] "D:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] D:\PROGRA~1\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [MimBoot] D:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\PROGRA~1\POP-UP~1\PSFREE.EXE"
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O10 - Unknown file in Winsock LSP: c:\program files\neoteris\secure application manager\gapsp.dll
O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet3_88.dll' missing
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://easyaccess.trinity-health.or...terisSetup.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1106450362857
O16 - DPF: {819EDD4C-7EB6-4D97-B831-D68B57E7D3ED} (Wyncs Control) - http://www.highschoolsports.net/Wyncs.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7214DB88-F77D-434D-AD3F-685A427DC728}: NameServer = 68.42.244.6,68.42.244.5
O20 - Winlogon Notify: WB - C:\PROGRA~1\STARDOCK\OBJECT~1\WINDOW~1\fastload.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unknown owner - D:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\PROGRA~1\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\PROGRA~1\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Photoshop Elements Device Connect (PhotoshopElementsDeviceConnect) - Unknown owner - D:\Program Files\Adobe\Photoshop Elements 3.0\PhotoshopElementsDeviceConnect.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - D:\Program Files\Sandra Lite\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - D:\Program Files\Sandra Lite\RpcSandraSrv.exe
O23 - Service: WARSVR - Unknown owner - D:\Program Files\War-ftpd\war-ftpd.exe" -tag WARSVR (file missing)


End of KRC HijackThis Analyzer Log.
====================================================================
cee is offline