UNSOLVED

fuzzyslipers75

updated

21 years ago

0

2527

November 4th, 2005 00:00

vitumundo help plz(hijack this log)

I have both ad-aware SE and microsoft antispyware telling me that I have the virtumundo adware trojan file, and I ran both the FixVundo.exe and the VirtumundoBeGone.exe programs, which say that they can't find the trojan.
here is my hijack this logfile:
 
Logfile of HijackThis v1.99.1
Scan saved at 9:45:34 PM, on 11/3/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
C:\Program Files\America Online 9.0b\waol.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\AOLHOS~1.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\AOLServiceHost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINDOWS\System32\cisvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
F:\program files\iPod\bin\iPodService.exe
C:\Program Files\America Online 9.0b\shellmon.exe
C:\WINDOWS\system32\cleanmgr.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\shotaim\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Money\System\urlmap.exe
C:\Program Files\hijack this\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1103755219\EE\AOLHostManager.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\shotaim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'xfire_lsp_8742.dll' missing
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://content.ancestry.families.aol.com/asfiles/files/install/MFImgVwr.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {B4618401-A5AD-4DED-AB0B-8B0F9CCE4B6A} (AMI Pictorial Control CWeb 2.1) - https://pacs.montefiore.org/amI/install/amiviewer.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1503/www.contentwatch.com/audit/includes/ContentAuditControl.cab
O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O18 - Filter: text/html - {2DE94081-9FE6-4227-BC59-B7A80CC8308C} - (no file)
O20 - Winlogon Notify: pmnlk - C:\WINDOWS\system32\pmnlk.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\program files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
 
 
 
 
 
help is greatly appreciated. thx
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    1357

    0

    Posted November 4th, 2005 13:00

    symantec also offers a Virutumundo Removal tool... let's see if it makes any difference:
     

    # Please download FixVMonde  from

    http://securityresponse.symantec.com/avcenter/FxVMonde.exe


    # Close all running programs (including your Internet Browser)... BE SURE TO SAVE ALL YOUR WORK!!

    # Locate the file that you just downloaded.


    # Double-click the FixVMonde.exe file to start the removal tool.

    # Click Start to begin the process, and then allow the tool to run.

    Important: Do not launch any new applications while the tool is running!

     

    when it's done, reboot your system.  if ad-aware and/or msft anti-spyware are still reporting a trojan, please copy/paste the ENTIRE/EXACT message you're receiving, including the NAME of any "infected" files, and the TYPE (Virtumonde??) of trojan it claims to find in each.

  • 1357

    0

    Posted November 6th, 2005 01:00

    #:21 [aolsp scheduler.exe]
    FilePath : C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\
    ProcessID : 236
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 1, 5, 0, 0
    ProductVersion : 1, 5, 0, 0
    ProductName : AOLSP Scheduler
    FileDescription : AOLSP Scheduler
    InternalName : AOLSP Scheduler
    LegalCopyright : Copyright (C) America Online, Inc. 2004
    OriginalFilename : AOLSP Scheduler.exe

    #:22 [mcvsescn.exe]
    FilePath : c:\progra~1\mcafee.com\vso\
    ProcessID : 248
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 10, 0, 0, 20
    ProductVersion : 10, 0, 0, 0
    ProductName : McAfee VirusScan
    CompanyName : McAfee, Inc.
    FileDescription : McAfee VirusScan E-mail Scan Module
    InternalName : mcvsescn
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : mcvsescn.EXE
    Comments : McAfee VirusScan E-mail Scan Module

    #:23 [onetouch.exe]
    FilePath : C:\PROGRA~1\Maxtor\OneTouch\Utils\
    ProcessID : 276
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 2, 0, 0, 0
    ProductVersion : 2, 0, 0, 0
    ProductName : Maxtor OneTouch
    CompanyName : Maxtor
    FileDescription : Maxtor OneTouch Detection
    InternalName : ComboButton
    LegalCopyright : Copyright (C) 2003 Maxtor Corp.
    OriginalFilename : OneTouch.EXE

    #:24 [mxoaldr.exe]
    FilePath : C:\WINDOWS\
    ProcessID : 284
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 6.00.1010.0
    ProductVersion : 6.00.1010.0
    ProductName : MXO Storage Adapter
    CompanyName : Cypress Semiconductor
    FileDescription : Maxtor MXO Auto Loader Application
    InternalName : MXOALDR.EXE
    LegalCopyright : Copyright (C) 1998-2002 Cypress Semiconductor
    OriginalFilename : MXOALDR.EXE

    #:25 [jusched.exe]
    FilePath : C:\Program Files\Java\j2re1.4.2_05\bin\
    ProcessID : 304
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal


    #:26 [hpcmpmgr.exe]
    FilePath : C:\Program Files\HP\hpcoretech\
    ProcessID : 316
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 2.1.1.0
    ProductVersion : 2.1.4
    ProductName : hp coretech (COmponent REuse TECHnology)
    CompanyName : Hewlett-Packard Company
    FileDescription : HP Framework Component Manager Service
    InternalName : HPComponentManagerService module
    LegalCopyright : Copyright (C) Hewlett-Packard. 2002-2003
    OriginalFilename : HpCmpMgr.exe

    #:27 [hpwuschd.exe]
    FilePath : C:\Program Files\HP\HP Software Update\
    ProcessID : 336
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 1, 0, 0, 3
    ProductVersion : 1, 0, 0, 3
    ProductName : Hewlett-Packard hpwuSchd
    CompanyName : Hewlett-Packard
    FileDescription : hpwuSchd
    InternalName : hpwuSchd
    LegalCopyright : Copyright © 2003
    OriginalFilename : hpwuSchd.exe

    #:28 [gcasserv.exe]
    FilePath : C:\Program Files\Microsoft AntiSpyware\
    ProcessID : 384
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Idle
    FileVersion : 1.00.0615
    ProductVersion : 1.00.0615
    ProductName : Microsoft AntiSpyware (Beta 1)
    CompanyName : Microsoft Corporation
    FileDescription : Microsoft AntiSpyware Service
    InternalName : gcasServ
    LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
    LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet(tm) is a trademark of Microsoft Corporation.
    OriginalFilename : gcasServ.exe

    #:29 [rundll32.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 408
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Run a DLL as an App
    InternalName : rundll
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : RUNDLL.EXE

    #:30 [oasclnt.exe]
    FilePath : C:\Program Files\McAfee.com\VSO\
    ProcessID : 416
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 10, 0, 0, 24
    ProductVersion : 10, 0, 0, 0
    ProductName : McAfee VirusScan
    CompanyName : McAfee, Inc.
    FileDescription : McAfee VirusScan OAS Client
    InternalName : OasClnt
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : OasClnt.exe
    Comments : McAfee VirusScan OAS Client

    #:31 [winampa.exe]
    FilePath : C:\Program Files\Winamp\
    ProcessID : 488
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal


    #:32 [ituneshelper.exe]
    FilePath : C:\Program Files\iTunes\
    ProcessID : 500
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 6.0.1.3
    ProductVersion : 6.0.1.3
    ProductName : iTunes
    CompanyName : Apple Computer, Inc.
    FileDescription : iTunesHelper Module
    InternalName : iTunesHelper
    LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename : iTunesHelper.exe

    #:33 [qttask.exe]
    FilePath : C:\Program Files\QuickTime\
    ProcessID : 512
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 7.0.3
    ProductVersion : QuickTime 7.0.3
    ProductName : QuickTime
    CompanyName : Apple Computer, Inc.
    FileDescription : QuickTime Task
    InternalName : QuickTime Task
    LegalCopyright : Copyright Apple Computer, Inc. 1989-2005
    OriginalFilename : QTTask.exe

    #:34 [mmdiag.exe]
    FilePath : C:\PROGRA~1\MUSICM~1\MUSICM~1\
    ProcessID : 528
    ThreadCreationTime : 11-4-2005 1:11:42 AM
    BasePriority : Normal
    FileVersion : 10.00.3058
    ProductVersion : 10.00.3058
    ProductName : Musicmatch Jukebox
    CompanyName : Musicmatch, Inc.
    FileDescription : Logging and tracing manager
    InternalName : MMTraceExe
    LegalCopyright : Copyright © Musicmatch 1998-2004
    LegalTrademarks :
    OriginalFilename : MMTraceExe.EXE

    #:35 [hpqtra08.exe]
    FilePath : C:\Program Files\HP\Digital Imaging\bin\
    ProcessID : 560
    ThreadCreationTime : 11-4-2005 1:11:43 AM
    BasePriority : Normal
    FileVersion : 5.35.0.035
    ProductVersion : 005.035.000.035
    ProductName : hp digital imaging - hp all-in-one series
    CompanyName : Hewlett-Packard Co.
    FileDescription : HP Digital Imaging Monitor (CUE)
    InternalName : HPQTRA00
    LegalCopyright : Copyright (C) Hewlett-Packard Co. 1995-2001
    OriginalFilename : HPQTRA00.EXE
    Comments : HP Digital Imaging Monitor (CUE)

    #:36 [mim.exe]
    FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
    ProcessID : 604
    ThreadCreationTime : 11-4-2005 1:11:43 AM
    BasePriority : Normal
    FileVersion : 10.00.3058
    ProductVersion : 10.00.3058
    ProductName : Musicmatch Jukebox
    CompanyName : Musicmatch, Inc.
    FileDescription : mim
    InternalName : mim
    LegalCopyright : Copyright © Musicmatch 1998-2004
    LegalTrademarks :
    OriginalFilename : mim.exe

    #:37 [aolhos~1.exe]
    FilePath : C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\
    ProcessID : 112
    ThreadCreationTime : 11-4-2005 1:11:44 AM
    BasePriority : Normal
    FileVersion : 1.0.0.6
    ProductVersion : 1.0.0.6
    ProductName : AOL Service Libraries
    CompanyName : America Online, Inc.
    FileDescription : AOLHostManager Service
    InternalName : AOLHostManager
    LegalCopyright : © 2004 America Online, Inc.
    OriginalFilename : AOLHostManager.exe

    #:38 [mpfagent.exe]
    FilePath : C:\PROGRA~1\McAfee.com\PERSON~1\
    ProcessID : 1136
    ThreadCreationTime : 11-4-2005 1:11:45 AM
    BasePriority : Normal
    FileVersion : 7.0.0.152
    ProductVersion : 7.0.0.152
    ProductName : McAfee Personal Firewall (MPF)
    CompanyName : McAfee Security
    FileDescription : McAfee Personal Firewall Agent Interface
    InternalName : MpfAgent
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : MPFAGENT.EXE
    Comments : McAfee Personal Firewall Security Center Module

    #:39 [aolservicehost.exe]
    FilePath : C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\
    ProcessID : 1148
    ThreadCreationTime : 11-4-2005 1:11:46 AM
    BasePriority : Normal
    FileVersion : 1.0.0.6
    ProductVersion : 1.0.0.6
    ProductName : AOL Service Libraries
    CompanyName : America Online, Inc.
    FileDescription : AOLServiceHost Service
    InternalName : AOLServiceHost
    LegalCopyright : © 2004 America Online, Inc.
    OriginalFilename : AOLServiceHost.exe

    #:40 [gcasdtserv.exe]
    FilePath : C:\Program Files\Microsoft AntiSpyware\
    ProcessID : 1540
    ThreadCreationTime : 11-4-2005 1:11:47 AM
    BasePriority : Normal
    FileVersion : 1.00.0615
    ProductVersion : 1.00.0615
    ProductName : Microsoft AntiSpyware (Beta 1)
    CompanyName : Microsoft Corporation
    FileDescription : Microsoft AntiSpyware Data Service
    InternalName : gcasDtServ
    LegalCopyright : Copyright © 2004-2005 Microsoft Corporation. All rights reserved.
    LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation. SpyNet(tm) is a trademark of Microsoft Corporation.
    OriginalFilename : gcasDtServ.exe

    #:41 [aolacsd.exe]
    FilePath : C:\Program Files\Common Files\AOL\ACS\
    ProcessID : 1564
    ThreadCreationTime : 11-4-2005 1:11:48 AM
    BasePriority : Normal
    FileVersion : 3.0.0.1
    ProductVersion : 3.0.0.1
    ProductName : AOL Connectivity Service
    CompanyName : America Online
    FileDescription : AOL Connectivity Service
    InternalName : AOLacsd
    LegalCopyright : Copyright © 2004 America Online
    OriginalFilename : AOLacsd.exe

    #:42 [aoltsmon.exe]
    FilePath : C:\Program Files\Common Files\AOL\TopSpeed\2.0\
    ProcessID : 1316
    ThreadCreationTime : 11-4-2005 1:11:49 AM
    BasePriority : Normal
    FileVersion : 2, 0, 0, 0
    ProductVersion : 2, 0, 0, 0
    ProductName : AOL TopSpeed(TM) Monitor
    CompanyName : America Online, Inc
    FileDescription : AOL TopSpeed(TM) Monitor
    InternalName : AOL TopSpeed(TM) Monitor
    LegalCopyright : Copyright © 2004 America Online, Inc.
    OriginalFilename : aoltsmon.exe

    #:43 [cisvc.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 1952
    ThreadCreationTime : 11-4-2005 1:11:52 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Content Index service
    InternalName : cisvc.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : cisvc.exe

    #:44 [mcdetect.exe]
    FilePath : c:\program files\mcafee.com\agent\
    ProcessID : 2176
    ThreadCreationTime : 11-4-2005 1:11:57 AM
    BasePriority : Normal
    FileVersion : 6, 0, 0, 19
    ProductVersion : 6, 0, 0, 0
    ProductName : McAfee SecurityCenter
    CompanyName : McAfee, Inc
    FileDescription : McAfee WSC Integration Service
    InternalName : McDetect
    LegalCopyright : Copyright © 2005 McAfee, Inc.
    OriginalFilename : McDetect.exe
    Comments : McAfee WSC Integration Service

    #:45 [aoltpspd.exe]
    FilePath : C:\Program Files\Common Files\AOL\TopSpeed\2.0\
    ProcessID : 2184
    ThreadCreationTime : 11-4-2005 1:11:57 AM
    BasePriority : Normal
    FileVersion : 2, 0, 0, 0
    ProductVersion : 2, 0, 0, 0
    ProductName : AOL TopSpeed(TM)
    CompanyName : America Online Inc
    FileDescription : AOL TopSpeed(TM)
    InternalName : AOL TopSpeed(TM) Loader
    LegalCopyright : Copyright © 2003-2004
    LegalTrademarks : AOL TopSpeed(TM)
    OriginalFilename : aoltpspd.exe
  • 1357

    0

    Posted November 6th, 2005 01:00

    #:46 [mcshield.exe]
    FilePath : c:\PROGRA~1\mcafee.com\vso\
    ProcessID : 2244
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : High


    #:47 [mctskshd.exe]
    FilePath : c:\PROGRA~1\mcafee.com\agent\
    ProcessID : 2308
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : Normal
    FileVersion : 6, 0, 0, 13
    ProductVersion : 6, 0, 0, 0
    ProductName : McAfee SecurityCenter
    CompanyName : McAfee, Inc
    FileDescription : McAfee Task Scheduler
    InternalName : McTskshd
    LegalCopyright : Copyright © 2005 McAfee, Inc.
    OriginalFilename : McTskshd.exe

    #:48 [mpfservice.exe]
    FilePath : C:\PROGRA~1\McAfee.com\PERSON~1\
    ProcessID : 2412
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : Normal
    FileVersion : 7.0.0.152
    ProductVersion : 7.0.0.152
    ProductName : McAfee Personal Firewall
    CompanyName : McAfee Corporation
    FileDescription : McAfee Personal Firewall Service
    InternalName : MPFService
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : MpfService.exe
    Comments : McAfee Personal Firewall Service

    #:49 [nvsvc32.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 2448
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : Normal
    FileVersion : 6.14.10.5216
    ProductVersion : 6.14.10.5216
    ProductName : NVIDIA Driver Helper Service, Version 52.16
    CompanyName : NVIDIA Corporation
    FileDescription : NVIDIA Driver Helper Service, Version 52.16
    InternalName : NVSVC
    LegalCopyright : (C) NVIDIA Corporation. All rights reserved.
    OriginalFilename : nvsvc32.exe

    #:50 [retrorun.exe]
    FilePath : C:\Program Files\Dantz\Retrospect\
    ProcessID : 2508
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : Normal
    FileVersion : 6.0.222
    ProductVersion : 6.0
    ProductName : Retrospect
    CompanyName : Dantz Development Corporation
    FileDescription : Retrospect
    InternalName :
    LegalCopyright : Copyright Dantz 1989-2002
    LegalTrademarks : Dantz® Retrospect®
    OriginalFilename : retrorun.exe

    #:51 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 2648
    ThreadCreationTime : 11-4-2005 1:11:58 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:52 [wdfmgr.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 2672
    ThreadCreationTime : 11-4-2005 1:11:59 AM
    BasePriority : Normal
    FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
    ProductVersion : 5.2.3790.1230
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Windows User Mode Driver Manager
    InternalName : WdfMgr
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : WdfMgr.exe

    #:53 [wanmpsvc.exe]
    FilePath : C:\WINDOWS\
    ProcessID : 2712
    ThreadCreationTime : 11-4-2005 1:11:59 AM
    BasePriority : Normal
    FileVersion : 7, 0, 0, 2
    ProductVersion : 7, 0, 0, 2
    ProductName : America Online
    CompanyName : America Online, Inc.
    FileDescription : Wan Miniport (ATW) Service
    InternalName : WanMPSvc
    LegalCopyright : Copyright © 2001 America Online, Inc.
    OriginalFilename : WanMPSvc.exe

    #:54 [wmiprvse.exe]
    FilePath : C:\WINDOWS\System32\wbem\
    ProcessID : 3304
    ThreadCreationTime : 11-4-2005 1:12:01 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : WMI
    InternalName : Wmiprvse.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : Wmiprvse.exe

    #:55 [ipodservice.exe]
    FilePath : F:\program files\iPod\bin\
    ProcessID : 3624
    ThreadCreationTime : 11-4-2005 1:12:11 AM
    BasePriority : Normal
    FileVersion : 6.0.1.3
    ProductVersion : 6.0.1.3
    ProductName : iTunes
    CompanyName : Apple Computer, Inc.
    FileDescription : iPodService Module
    InternalName : iPodService
    LegalCopyright : © 2003-2005 Apple Computer, Inc. All Rights Reserved.
    OriginalFilename : iPodService.exe

    #:56 [alg.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 3160
    ThreadCreationTime : 11-4-2005 1:12:56 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Application Layer Gateway Service
    InternalName : ALG.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : ALG.exe

    #:57 [cidaemon.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 3536
    ThreadCreationTime : 11-4-2005 1:18:58 AM
    BasePriority : Idle
    FileVersion : 5.1.2600.0 (xpclient.010817-1148)
    ProductVersion : 5.1.2600.0
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Indexing Service filter daemon
    InternalName : cidaemon.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : cidaemon.exe

    #:58 [aim.exe]
    FilePath : C:\Program Files\shotaim\
    ProcessID : 712
    ThreadCreationTime : 11-4-2005 2:43:14 AM
    BasePriority : Normal
    FileVersion : 5.9.3861
    ProductVersion : 5.9.3861
    ProductName : AOL Instant Messenger
    CompanyName : America Online, Inc.
    FileDescription : AOL Instant Messenger
    InternalName : AIM
    LegalCopyright : Copyright © 1996-2005 America Online, Inc.
    OriginalFilename : AIM.EXE

    #:59 [mcvsftsn.exe]
    FilePath : c:\progra~1\mcafee.com\vso\
    ProcessID : 1196
    ThreadCreationTime : 11-4-2005 2:43:31 AM
    BasePriority : Normal
    FileVersion : 10, 0, 0, 19
    ProductVersion : 10, 0, 0, 0
    ProductName : McAfee VirusScan
    CompanyName : McAfee, Inc.
    FileDescription : McAfee VirusScan Instant Messenger Scan Module
    InternalName : mcvsftsn
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : mcvsftsn.EXE
    Comments : McAfee VirusScan Instant Messenger Scan Module

    #:60 [msmsgs.exe]
    FilePath : C:\Program Files\Messenger\
    ProcessID : 400
    ThreadCreationTime : 11-4-2005 2:43:39 AM
    BasePriority : Normal
    FileVersion : 4.7.3001
    ProductVersion : Version 4.7.3001
    ProductName : Messenger
    CompanyName : Microsoft Corporation
    FileDescription : Windows Messenger
    InternalName : msmsgs
    LegalCopyright : Copyright (c) Microsoft Corporation 2004
    LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
    OriginalFilename : msmsgs.exe

    #:61 [hptskmgr.exe]
    FilePath : C:\Program Files\HP\hpcoretech\comp\
    ProcessID : 3960
    ThreadCreationTime : 11-4-2005 1:12:58 PM
    BasePriority : Normal
    FileVersion : 2.1.4
    ProductVersion : 2.1.4
    ProductName : hp coretech (COmponent REuse TECHnology)
    CompanyName : Hewlett-Packard Company
    FileDescription : HP Task Management Component
    InternalName : HP Task Management Component
    LegalCopyright : Copyright (C) Hewlett-Packard. 2002-2003
    OriginalFilename : HPTskMgr.exe

    #:62 [photocd.exe]
    FilePath : D:\
    ProcessID : 540
    ThreadCreationTime : 11-4-2005 8:23:57 PM
    BasePriority : Normal


    #:63 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 3172
    ThreadCreationTime : 11-5-2005 9:50:14 PM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:64 [realsched.exe]
    FilePath : C:\Program Files\Common Files\Real\Update_OB\
    ProcessID : 1452
    ThreadCreationTime : 11-6-2005 1:11:57 AM
    BasePriority : Normal
    FileVersion : 0.1.0.3018
    ProductVersion : 0.1.0.3018
    ProductName : RealPlayer (32-bit)
    CompanyName : RealNetworks, Inc.
    FileDescription : RealNetworks Scheduler
    InternalName : schedapp
    LegalCopyright : Copyright © RealNetworks, Inc. 1995-2004
    LegalTrademarks : RealAudio(tm) is a trademark of RealNetworks, Inc.
    OriginalFilename : realsched.exe

    #:65 [waol.exe]
    FilePath : C:\Program Files\America Online 9.0b\
    ProcessID : 3588
    ThreadCreationTime : 11-6-2005 1:24:53 AM
    BasePriority : Idle


    #:66 [shellmon.exe]
    FilePath : C:\Program Files\America Online 9.0b\
    ProcessID : 204
    ThreadCreationTime : 11-6-2005 1:25:06 AM
    BasePriority : Idle


    #:67 [ad-aware.exe]
    FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
    ProcessID : 5364
    ThreadCreationTime : 11-6-2005 3:11:41 AM
    BasePriority : Normal
    FileVersion : 6.2.0.236
    ProductVersion : SE 106
    ProductName : Lavasoft Ad-Aware SE
    CompanyName : Lavasoft Sweden
    FileDescription : Ad-Aware SE Core application
    InternalName : Ad-Aware.exe
    LegalCopyright : Copyright © Lavasoft AB Sweden
    OriginalFilename : Ad-Aware.exe
    Comments : All Rights Reserved

    #:68 [firefox.exe]
    FilePath : C:\Program Files\Mozilla Firefox\
    ProcessID : 312
    ThreadCreationTime : 11-6-2005 3:11:50 AM
    BasePriority : Normal


    Memory scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 0


    Started registry scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Virtumonde Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 10
    Category : Malware
    Comment :
    Rootkey : HKEY_CLASSES_ROOT
    Object : msevents.msevents.1

    Registry Scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 1
    Objects found so far: 1


    Started deep registry scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Deep registry scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 1


    Started Tracking Cookie scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


    Tracking cookie scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 1



    Deep scanning and examining files...
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Disk Scan Result for C:\WINDOWS
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 1

    Disk Scan Result for C:\WINDOWS\system32
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 1

    Disk Scan Result for C:\DOCUME~1\alan\LOCALS~1\Temp\
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 0
    Objects found so far: 1


    Scanning Hosts file......
    Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Hosts file scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    1 entries scanned.
    New critical objects:0
    Objects found so far: 1



    MRU List Object Recognized!
    Location: : C:\Documents and Settings\alan\Application Data\microsoft\office\recent
    Description : list of recently opened documents using microsoft office



    Performing conditional scans...
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Virtumonde Object Recognized!
    Type : Regkey
    Data :
    TAC Rating : 10
    Category : Malware
    Comment :
    Rootkey : HKEY_CLASSES_ROOT
    Object : .key

    Conditional scan result:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    New critical objects: 1
    Objects found so far: 3

    10:21:20 PM Scan Complete

    Summary Of This Scan
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    Total scanning time:00:01:04.172
    Objects scanned:96834
    Objects identified:2
    Objects ignored:0
    New critical objects:2

    In the scan summary tab, the name of the detected item is called "Virtumonde (2 objects total)" and in the critical objects tab, it says that the 2 virtumonde files are Regkeys and Malwares. There are 2 different objects.
    one is "HKEY_CLASSES_ROOT:msevents.msevents.1\"
    the other is "HKEY_CLASSES_ROOT:.key\"

    Message Edited by fuzzyslipers75 on 11-05-2005 09:37 PM

  • 1357

    0

    Posted November 6th, 2005 01:00

    I ran the FixVMonde.exe and it, also, said that there was no instance of the trojan. I ran Ad-Aware SE and this is the log of it:



    Ad-Aware SE Build 1.06r1
    Logfile Created on:Saturday, November 05, 2005 10:20:16 PM
    Created with Ad-Aware SE Personal, free for private use.
    Using definitions file:SE1R73 03.11.2005
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    References detected during the scan:
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
    MRU List(TAC index:0):1 total references
    Virtumonde(TAC index:10):2 total references
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    Definition File:
    =========================
    Definitions File Loaded:
    Reference Number : SE1R73 03.11.2005
    Internal build : 85
    File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
    File size : 541521 Bytes
    Total size : 1624315 Bytes
    Signature data size : 1590701 Bytes
    Reference data size : 33102 Bytes
    Signatures total : 45108
    CSI Fingerprints total : 1068
    CSI data size : 38355 Bytes
    Target categories : 15
    Target families : 769


    Memory + processor status:
    ==========================
    Number of processors : 1
    Processor architecture : Intel Pentium IV
    Memory available:61 %
    Total physical memory:1571820 kb
    Available physical memory:956856 kb
    Total page file size:3516972 kb
    Available on page file:3014236 kb
    Total virtual memory:2097024 kb
    Available virtual memory:2015724 kb
    OS:Microsoft Windows XP Professional Service Pack 2 (Build 2600)

    Ad-Aware SE Settings
    ===========================
    Set : Search for negligible risk entries
    Set : Search for low-risk threats
    Set : Safe mode (always request confirmation)
    Set : Scan active processes
    Set : Scan registry
    Set : Deep-scan registry
    Set : Scan my IE Favorites for banned URLs
    Set : Scan within archives
    Set : Scan my Hosts file

    Extended Ad-Aware SE Settings
    ===========================
    Set : Unload recognized processes & modules during scan
    Set : Scan registry for all users instead of current user only
    Set : Always try to unload modules before deletion
    Set : During removal, unload Explorer and IE if necessary
    Set : Let Windows remove files in use at next reboot
    Set : Delete quarantined objects after restoring
    Set : Include basic Ad-Aware settings in log file
    Set : Include additional Ad-Aware settings in log file
    Set : Include reference summary in log file
    Set : Include alternate data stream details in log file
    Set : Play sound at scan completion if scan locates critical objects


    11-5-2005 10:20:16 PM - Scan started. (Smart mode)

    Listing running processes
    »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

    #:1 [smss.exe]
    FilePath : \SystemRoot\System32\
    ProcessID : 724
    ThreadCreationTime : 11-4-2005 1:11:25 AM
    BasePriority : Normal


    #:2 [csrss.exe]
    FilePath : \??\C:\WINDOWS\system32\
    ProcessID : 780
    ThreadCreationTime : 11-4-2005 1:11:36 AM
    BasePriority : Normal


    #:3 [winlogon.exe]
    FilePath : \??\C:\WINDOWS\system32\
    ProcessID : 804
    ThreadCreationTime : 11-4-2005 1:11:36 AM
    BasePriority : High


    #:4 [services.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 848
    ThreadCreationTime : 11-4-2005 1:11:36 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Services and Controller app
    InternalName : services.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : services.exe

    #:5 [lsass.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 860
    ThreadCreationTime : 11-4-2005 1:11:36 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : LSA Shell (Export Version)
    InternalName : lsass.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : lsass.exe

    #:6 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1016
    ThreadCreationTime : 11-4-2005 1:11:37 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:7 [svchost.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1072
    ThreadCreationTime : 11-4-2005 1:11:37 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:8 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 1168
    ThreadCreationTime : 11-4-2005 1:11:37 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:9 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 1224
    ThreadCreationTime : 11-4-2005 1:11:37 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:10 [svchost.exe]
    FilePath : C:\WINDOWS\System32\
    ProcessID : 1268
    ThreadCreationTime : 11-4-2005 1:11:38 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 5.1.2600.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Generic Host Process for Win32 Services
    InternalName : svchost.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : svchost.exe

    #:11 [explorer.exe]
    FilePath : C:\WINDOWS\
    ProcessID : 1648
    ThreadCreationTime : 11-4-2005 1:11:39 AM
    BasePriority : Normal
    FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
    ProductVersion : 6.00.2900.2180
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Windows Explorer
    InternalName : explorer
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : EXPLORER.EXE

    #:12 [lexbces.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1728
    ThreadCreationTime : 11-4-2005 1:11:39 AM
    BasePriority : Normal
    FileVersion : 7.4
    ProductVersion : 7.4
    ProductName : MarkVision for Windows (32 bit)
    CompanyName : Lexmark International, Inc.
    FileDescription : LexBce Service
    InternalName : LexBce Service
    LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
    OriginalFilename : LexBceS.exe

    #:13 [spoolsv.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1752
    ThreadCreationTime : 11-4-2005 1:11:39 AM
    BasePriority : Normal
    FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
    ProductVersion : 5.1.2600.2696
    ProductName : Microsoft® Windows® Operating System
    CompanyName : Microsoft Corporation
    FileDescription : Spooler SubSystem App
    InternalName : spoolsv.exe
    LegalCopyright : © Microsoft Corporation. All rights reserved.
    OriginalFilename : spoolsv.exe

    #:14 [lexpps.exe]
    FilePath : C:\WINDOWS\system32\
    ProcessID : 1804
    ThreadCreationTime : 11-4-2005 1:11:39 AM
    BasePriority : Normal
    FileVersion : 7.4
    ProductVersion : 7.4
    ProductName : MarkVision for Windows (32 bit)
    CompanyName : Lexmark International, Inc.
    FileDescription : LEXPPS.EXE
    InternalName : LEXPPS
    LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
    OriginalFilename : LEXPPS.EXE
    Comments : MarkVision for Windows '95 New P2P Server (32-bit)

    #:15 [bcmsmmsg.exe]
    FilePath : C:\WINDOWS\
    ProcessID : 1912
    ThreadCreationTime : 11-4-2005 1:11:40 AM
    BasePriority : Normal
    FileVersion : 3.5.25 08/27/2003 20:04:35
    ProductVersion : 3.5.25 08/27/2003 20:04:35
    ProductName : BCM Modem Messaging Applet
    CompanyName : Broadcom Corporation
    FileDescription : Modem Messaging Applet
    InternalName : smdmstat.exe
    LegalCopyright : Copyright © Broadcom Corporation 1998-2000
    OriginalFilename : smdmstat.exe

    #:16 [mm_tray.exe]
    FilePath : C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\
    ProcessID : 1920
    ThreadCreationTime : 11-4-2005 1:11:40 AM
    BasePriority : Normal
    FileVersion : 10.00.3058
    ProductVersion : 10.00.3058
    ProductName : Musicmatch Jukebox
    CompanyName : Musicmatch, Inc.
    FileDescription : mm_tray
    InternalName : mm_tray
    LegalCopyright : Copyright © Musicmatch 1998-2004
    LegalTrademarks :
    OriginalFilename : mm_tray.exe

    #:17 [mcvsshld.exe]
    FilePath : C:\Program Files\McAfee.com\VSO\
    ProcessID : 2016
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 10, 0, 0, 22
    ProductVersion : 10, 0, 0, 0
    ProductName : McAfee VirusScan
    CompanyName : McAfee, Inc.
    FileDescription : McAfee VirusScan ActiveShield Resource
    InternalName : McVsShld
    LegalCopyright : Copyright © 2005 McAfee, Inc. All Rights Reserved.
    OriginalFilename : McVsShld.exe
    Comments : McAfee VirusScan ActiveShield Resource

    #:18 [mcagent.exe]
    FilePath : C:\PROGRA~1\mcafee.com\agent\
    ProcessID : 2028
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 6, 0, 0, 16
    ProductVersion : 6, 0, 0, 0
    ProductName : McAfee SecurityCenter
    CompanyName : McAfee, Inc
    FileDescription : McAfee SecurityCenter Agent
    InternalName : mcagent
    LegalCopyright : Copyright © 2005 McAfee, Inc.
    OriginalFilename : mcagent.exe

    #:19 [viewmgr.exe]
    FilePath : C:\Program Files\Viewpoint\Viewpoint Manager\
    ProcessID : 144
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 1, 0, 0, 43
    ProductVersion : 1, 0, 0, 43
    ProductName : Viewpoint Manager
    CompanyName : Viewpoint Corporation
    FileDescription : ViewMgr
    InternalName : Viewpoint Manager
    LegalCopyright : Copyright © 2004
    OriginalFilename : ViewMgr.exe
    Comments : Viewpoint Manager

    #:20 [aoldial.exe]
    FilePath : C:\Program Files\Common Files\AOL\ACS\
    ProcessID : 200
    ThreadCreationTime : 11-4-2005 1:11:41 AM
    BasePriority : Normal
    FileVersion : 3.0.0.1
    ProductVersion : 3.0.0.1
    ProductName : AOL Connectivity Service
    CompanyName : America Online
    FileDescription : AOL Connectivity Service Dialer
    InternalName : AOLdial
    LegalCopyright : Copyright © 2004 America Online
    OriginalFilename : AOLdial.exe
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    1357

    0

    Posted November 6th, 2005 12:00

    Looking back at your HJT log, there's a non-critical "remnant" of the Vundo/Virtumonde trojan still showing, which we can easily remove now:

    Run HiJackThis. Place a check-mark in the box in front of the line:

    O20 - Winlogon Notify: pmnlk - C:\WINDOWS\system32\pmnlk.dll (file missing)

    Click on FIX CHECKED. Close HiJackThis. Reboot.

    And then generate/post your updated HJT log.

                                        *********************

    A few questions for you:

    1)  Had [past tense] you been experiencing WinFixer popups?  And if so, have they stopped since you ran the FixVundo and/or the VirtumundoBeGoneprograms ?

    2) after the minor FIX (and reboot) we just tried, is Ad-Aware and/or Microsoft anti-spyware still reporting the two registry key problems?   Does either program offer you the chance to "fix" them? --- If so, have you tried? --- Or do they just come back after you "fix" them?

     

    On the assumption that you HAD a WinFixer popup problem, which stopped after FixVundo/V.BeGone (and if my "simple" fix didn't change the registry problem), my suspicion is that the trojan was successfully removed --- meaning that it's no longer running/impacting your PC --- but that, for some reason, a (non-harmful) "remnant" remains stuck in your registry.   When you post your updated log, if you still have the problem, i'm gonna ask someone else to step-in, to see if they can offer you another suggestion... as well as analyze the remainder of your HJT log for remaining problems, if any, that you might have [as I was focusing just on the one/"immediate" problem you've asked about]

     

     

     

  • 1357

    0

    Posted November 10th, 2005 20:00

    "O20 - Winlogon Notify: pmnlk - C:\WINDOWS\system32\pmnlk.dll (file missing)

    Click on FIX CHECKED. Close HiJackThis. Reboot."

    I did the fix, rebooted, and generated a logfile. Here is my new logfile from hijack this:

    Logfile of HijackThis v1.99.1
    Scan saved at 10:32:01 PM, on 11/9/2005
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\WINDOWS\BCMSMMSG.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
    C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    C:\WINDOWS\MXOALDR.EXE
    C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd.exe
    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\MUSICM~1\MUSICM~1\MMDiag.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mim.exe
    C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\AOLHOS~1.EXE
    C:\PROGRA~1\COMMON~1\AOL\110375~1\EE\AOLServiceHost.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\WINDOWS\System32\cisvc.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Dantz\Retrospect\retrorun.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\wanmpsvc.exe
    F:\program files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    C:\Program Files\shotaim\aim.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HPZSTC09.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\Program Files\America Online 9.0b\waol.exe
    C:\Program Files\America Online 9.0b\shellmon.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Microsoft Money\System\urlmap.exe
    C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
    C:\Program Files\hijack this\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.optonline.net
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.optonline.net/
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
    O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
    O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
    O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\Program Files\AIM95\\DeadAIM.ocm",ExportedCheckODLs
    O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
    O4 - HKLM\..\Run: [MXO Auto Loader] C:\WINDOWS\MXOALDR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1103755219\EE\AOLHostManager.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~1\mimboot.exe
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [Red Swoosh EDN Client] C:\Program Files\RSNet\RSEDNClient.exe
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0b\AOL.EXE" -b
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &FastSeeker Search - res://C:\Program Files\FastSeeker\FastSeekerToolbar.dll/cmsearch.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\shotaim\aim.exe
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Broken Internet access because of LSP provider 'xfire_lsp_8742.dll' missing
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,84/mcinsctl.cab
    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
    O16 - DPF: {75565ED2-1560-4F15-B841-20358DE6A0D1} (ImageControl Class) - http://content.ancestry.families.aol.com/asfiles/files/install/MFImgVwr.cab
    O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - http://echat.us.dell.com/Media/VisitorChat/TLIEFlash.CAB
    O16 - DPF: {AB29A544-D6B4-4E36-A1F8-D3E34FC7B00A} (WTHoster Class) - http://install.wildtangent.com/bgn/partners/ea/needforspeed/install.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {B4618401-A5AD-4DED-AB0B-8B0F9CCE4B6A} (AMI Pictorial Control CWeb 2.1) - https://pacs.montefiore.org/amI/install/amiviewer.cab
    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,21/mcgdmgr.cab
    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
    O16 - DPF: {CD17FAAA-17B4-4736-AAEF-436EDC304C8C} (ContentAuditX Control) - http://a840.g.akamai.net/7/840/5805/v1503/www.contentwatch.com/audit/includes/ContentAuditControl.cab
    O16 - DPF: {D0B5B58D-8CB9-4EDB-8BB0-9D34AEF727CF} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O18 - Filter: text/html - {2DE94081-9FE6-4227-BC59-B7A80CC8308C} - (no file)
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - F:\program files\iPod\bin\iPodService.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
    O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
    O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

    I ran Ad-Aware SE again, and the Virtumonde object still showed up, except this time, its 1 object total instead of 2
    type: regkey
    category: malware
    object: HKEY_CLASSES_ROOT:msevents.msevents.1\

    So 1 of the virtumonde objects is gone, but there is still one here.

    If I try to fix the problem in Ad-Aware SE, when I scan again, it shows up as still there. It also shows up in a Microsoft Anti-Spyware search. I can remove them, this is what it says I can remove:

    Infected registry keys/values detected
    Virtumondo(Adware)
    HKEY_CLASSES_ROOT\MSEvents.MSEvents.1
    HKEY_CLASSES_ROOT\MSEvents.MSEvents.1\CLSID {52B1DFC7-AAFC-4362-B103-868B0683C697}
    HKEY_CLASSES_ROOT\MSEvents.MSEvents.1 MSEvents Object
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1\CLSID {52B1DFC7-AAFC-4362-B103-868B0683C697}
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MSEvents.MSEvents.1 MSEvents Object

    When I run either Ad-Aware or Microsoft Antispyware after I remove it with Microsoft Anti-spyware, Virtumunde still shows up.
  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    1357

    0

    Posted November 11th, 2005 00:00

    you still neglected to answer a key question:  Had [past tense] you (at some point) been experiencing WinFixer popups?  And if so, have they stopped?

    as i said previously, my suspicion is that the trojan was successfully removed --- meaning that it's no longer running/impacting your PC --- but that, for some reason, a (non-harmful) "remnant" remains stuck in your registry.   

    at this point,  i'm gonna ask someone else to step-in, to see if they can offer you another suggestion... as well as analyze the remainder of your HJT log for remaining problems, if any, that you might have.

    good luck

  • ky331

    5 Journeyman

    15622 Posts

    45048 Points

    1362

    0

    Posted November 11th, 2005 15:00

    WinFixer can manifest itself in different ways... so i can't definitively say what you (or the owner) MIGHT have experienced.   suffice it to say that, if this particular problem were still there, you'd definitely see it.
     
    as mentioned, i've given the info about this thread to some other helpers, requesting them to follow-up on what we've already done.... so let's wait and see what they have to say when they arrive.
  • 1357

    0

    Posted November 11th, 2005 15:00

    I'm sorry about forgetting that question. I do not know what WinFixer popups are, and since the computer isn't mine, i dont know what to ask them about if they had these popups or not. Can you explain to me what a Winfixer popup is and what it looks like.
  • dobhar

    2 Intern

    1132 Posts

    1001

    0

    Posted November 11th, 2005 18:00

    Hi fuzzyslippers...
     
    My name is dobhar and I am following up on the great job you and ky331 did.  Please give me me a chance to go through your new log and I will post back as soon as possible.  If you have any questions please post back as a reply to this Thread\Topic and I will be advised by email so I can return and help you. Please do NOT start another Thread\Topic.
     
    Thanks,