Discussions Search    Reviews    Search Aid    Buzzzz    Google@Omgili Add to iGoogle   Bookmark and Share

  Advanced Search

Welcome to Omgili,
Omgili (Oh My God I Love It ;) is a search engine for discussions. With Omgili you can find answers and solutions, debates, discussions, personal experiences, opinions and more... To learn more about Omgili click here.

This is a complete preview of the discussion as it was indexed by Omgili crawlers. Use this preview if the original discussion is unavailable.
Click here to view the original discussion.
[http://forums.spybot.info/showthread.php?t=29835&mode=lin...]

Click here to search for discussions with Omgili discussions search engine.

Virtumonde help request - Safer Networking Forums

Spybot has detected Virtumonde on my laptop.

Have been reading all the posts but it seems a very individualized solution to destroy it so shall post my Hijackthis report and hope for the best. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:42:26 PM, on 6/21/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) \WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\system32\imapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Symantec AntiVirus\DoScan.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\acrobat_sl.exe C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Program Files\QUICKENW\QWDLLS.EXE C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DfrgNTFS.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll \Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo!

Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE O4 - Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html \Program Files\Java\jre1.6.0_05\bin\ssv.dll \Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll \Program Files\Messenger\msmsgs.exe \Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://download.windowsupdate.com O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: TabletService - Wacom Technology, Corp.

- C:\WINDOWS\system32\Tablet.exe O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe -- End of file - 9198 bytes

Hi DansMans Please post spybot report next

Hi Shaba, Strange thing happened.

I ran Spybot SD to generate a report and it said system was clean though I hadn't done anything to repair virtumonde.

I am including the log file from today followed by the one from 2 days prior to illustrate.

Thanks for the speedy reply. --- Search result list --- Congratulations!: No immediate threats were found.

() --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) --- 2008-01-28 blindman.exe (1.0.0.7) 2008-01-28 SDDelFile.exe (1.0.2.4) 2008-01-28 SDMain.exe (1.0.0.5) 2007-10-07 SDShred.exe (1.0.1.2) 2008-01-28 SDUpdate.exe (1.0.8.8) 2008-01-28 SDWinSec.exe (1.0.0.11) 2008-01-28 SpybotSD.exe (1.5.2.20) 2008-01-28 TeaTimer.exe (1.5.2.16) 2006-07-17 unins000.exe (51.41.0.0) 2008-06-12 unins001.exe (51.49.0.0) 2008-01-28 Update.exe (1.4.0.6) 2008-01-28 advcheck.dll (1.5.4.5) 2007-04-02 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2007-11-17 DelZip179.dll (1.79.7.4) 2008-01-28 SDFiles.dll (1.5.1.19) 2008-01-28 SDHelper.dll (1.5.0.11) 2008-01-28 Tools.dll (2.1.3.3) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2008-06-17 Includes\Adware.sbi (*) 2008-06-18 Includes\AdwareC.sbi (*) 2008-06-03 Includes\Cookies.sbi (*) 2008-06-03 Includes\Dialer.sbi (*) 2008-06-10 Includes\DialerC.sbi (*) 2008-06-03 Includes\HeavyDuty.sbi (*) 2008-06-16 Includes\Hijackers.sbi (*) 2008-06-17 Includes\HijackersC.sbi (*) 2008-06-03 Includes\Keyloggers.sbi (*) 2008-06-17 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2008-06-18 Includes\Malware.sbi (*) 2008-06-17 Includes\MalwareC.sbi (*) 2008-06-17 Includes\PUPS.sbi (*) 2008-06-17 Includes\PUPSC.sbi (*) 2007-11-07 Includes\Revision.sbi (*) 2008-06-10 Includes\Security.sbi (*) 2008-06-18 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2008-06-17 Includes\Spyware.sbi (*) 2008-06-17 Includes\SpywareC.sbi (*) 2008-06-03 Includes\Tracks.uti 2008-06-11 Includes\Trojans.sbi (*) 2008-06-18 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-06-06 Plugins\TCPIPAddress.dll --- System information --- Windows XP (Build: 2600) Service Pack 3 (5.1.2600) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Hotfix (KB928366) / .NETFramework / 1.1: Microsoft .NET Framework 1.1 Service Pack 1 (KB867460) / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB898458) / Step By Step Interactive Training / SP2: Security Update for Step By Step Interactive Training (KB923723) / Windows / SP1: Microsoft Internationalized Domain Names Mitigation APIs / Windows / SP1: Microsoft National Language Support Downlevel APIs / Windows Media Format 11 SDK: Hotfix for Windows Media Format 11 SDK (KB929399) / Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734) / Windows Media Player 11: Security Update for Windows Media Player 11 (KB936782) / Windows Media Player 11: Hotfix for Windows Media Player 11 (KB939683) / Windows Media Player 6.4: Security Update for Windows Media Player 6.4 (KB925398) / Windows XP: Security Update for Windows XP (KB923689) / Windows XP: Security Update for Windows XP (KB941569) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB928090) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB929969) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB931768) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB933566) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB937143) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB938127) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB939653) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB942615) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB944533) / Windows XP / SP0: Hotfix for Windows Internet Explorer 7 (KB947864) / Windows XP / SP0: Security Update for Windows Internet Explorer 7 (KB950759) / Windows XP / SP10: Microsoft Compression Client Pack 1.0 for Windows XP / Windows XP / SP3: Windows XP Service Pack 3 / Windows XP / SP4: Security Update for Windows XP (KB950760) / Windows XP / SP4: Security Update for Windows XP (KB950762) / Windows XP / SP4: Security Update for Windows XP (KB951376) / Windows XP / SP4: Security Update for Windows XP (KB951376-v2) / Windows XP / SP4: Security Update for Windows XP (KB951698) --- Startup entries list --- Located: HK_LM:Run, Acrobat Assistant 7.0 command: "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" file: C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe size: 483328 MD5: 78FF388FD58CE0BAE1F7C9670F5473C1 Located: HK_LM:Run, ccApp command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe size: 48752 MD5: 696F43558EA1C4BFF475A4B8ECC5CAC4 Located: HK_LM:Run, DiskeeperSystray command: "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" file: C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe size: 319488 MD5: 7D2A30EC96B9E5C37F889F8A724405BE Located: HK_LM:Run, dla command: C:\WINDOWS\system32\dla\tfswctrl.exe file: C:\WINDOWS\system32\dla\tfswctrl.exe size: 122939 MD5: 790490F273B0E3BCF05DC3C308ABCC0B Located: HK_LM:Run, HotKeysCmds command: C:\WINDOWS\system32\hkcmd.exe file: C:\WINDOWS\system32\hkcmd.exe size: 118784 MD5: EA5DD164296F66241BEAD39E12FA69F2 Located: HK_LM:Run, IgfxTray command: C:\WINDOWS\system32\igfxtray.exe file: C:\WINDOWS\system32\igfxtray.exe size: 155648 MD5: 8BBBADA96FFE1449EDD39256EDA99CD8 Located: HK_LM:Run, mmtask command: "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" file: C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe size: 53248 MD5: EFEA5551E578FF6FE52B5DB15CE13390 Located: HK_LM:Run, SunJavaUpdateSched command: "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" file: C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe size: 144784 MD5: 836DC47E6CAD975304D1D3EB2F516A1C Located: HK_LM:Run, vptray command: C:\PROGRA~1\SYMANT~1\VPTray.exe file: C:\PROGRA~1\SYMANT~1\VPTray.exe size: 85184 MD5: 1B5036466136A1451BDBA17B6AEBECB3 Located: HK_CU:Run, ctfmon.exe where: S-1-5-21-3293455119-3754554726-1239431001-1007... command: C:\WINDOWS\system32\ctfmon.exe file: C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 Located: HK_CU:Run, SpybotSD TeaTimer where: S-1-5-21-3293455119-3754554726-1239431001-1007... command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 2097488 MD5: A9A5DB6AC3721BE698B996913693D73F Located: HK_CU:Run, updateMgr where: S-1-5-21-3293455119-3754554726-1239431001-1007... command: "C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1 file: C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe size: 313472 MD5: 43F3F6D33C793089A7C32B45DA16094B Located: HK_CU:Run, Yahoo!

Pager where: S-1-5-21-3293455119-3754554726-1239431001-1007... command: "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet file: C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe size: 4662776 MD5: BB5E7B73A3A54CCF329325807E5122FE Located: Startup (common), Adobe Acrobat Speed Launcher.lnk where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760- 2}\SC_Acrobat.exe file: C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760- 2}\SC_Acrobat.exe size: 25214 MD5: D6294D59171AC375CD142003566AA89E Located: Startup (common), Adobe Reader Speed Launch.lnk where: C:\Documents and Settings\All Users\Start Menu\Programs\Startup... command: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe file: C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe size: 29696 MD5: 43362B96870CE8649F4F2EC893DA93F0 Located: Startup (user), Adobe Gamma.lnk where: C:\Documents and Settings\lnm\Start Menu\Programs\Startup... command: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe file: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe size: 113664 MD5: C2FF17734176CD15221C10044EF0BA1A Located: Startup (user), Billminder.lnk where: C:\Documents and Settings\lnm\Start Menu\Programs\Startup... command: C:\Program Files\QUICKENW\BILLMIND.EXE file: C:\Program Files\QUICKENW\BILLMIND.EXE size: 36864 MD5: A37F9D8FE33AC972E8756ABCF91E1855 Located: Startup (user), Quicken Startup.lnk where: C:\Documents and Settings\lnm\Start Menu\Programs\Startup... command: C:\Program Files\QUICKENW\QWDLLS.EXE file: C:\Program Files\QUICKENW\QWDLLS.EXE size: 36864 MD5: CAF57D1DCCA05A680C4E391054E6051E Located: Startup (disabled), America Online 9.0 Tray Icon (DISABLED) command: C:\PROGRA~1\AMERIC~1.0\aoltray.exe -check file: size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: Startup (disabled), Digital Line Detect (DISABLED) command: C:\PROGRA~1\DIGITA~1\DLG.exe file: C:\PROGRA~1\DIGITA~1\DLG.exe size: 24576 MD5: B66E56733E2CD6A10FDA5919625FBF46 Located: WinLogon, crypt32chain command: crypt32.dll file: crypt32.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cryptnet command: cryptnet.dll file: cryptnet.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, cscdll command: cscdll.dll file: cscdll.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, dimsntfy command: %SystemRoot%\System32\dimsntfy.dll file: %SystemRoot%\System32\dimsntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, igfxcui command: igfxsrvc.dll file: igfxsrvc.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, NavLogon command: C:\WINDOWS\system32\NavLogon.dll file: C:\WINDOWS\system32\NavLogon.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, ScCertProp command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, Schedule command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, sclgntfy command: sclgntfy.dll file: sclgntfy.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, SensLogn command: WlNotify.dll file: WlNotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, termsrv command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, WgaLogon command: WgaLogon.dll file: WgaLogon.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! Located: WinLogon, wlballoon command: wlnotify.dll file: wlnotify.dll size: 0 MD5: D41D8CD98F00B204E9800998ECF8427E Warning: if the file is actually larger than 0 bytes, the checksum could not be properly calculated! --- Browser helper object list --- {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Adobe PDF Reader Link Helper description: Adobe Acrobat reader classification: Legitimate known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll info link: http://www.adobe.com/products/acrobat/readstep2.html info source: TonyKlein Path: C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\ Long name: AcroIEHelper.dll Short name: ACROIE~1.DLL Date (created): 9/23/2005 10:12:08 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 1/12/2006 9:38:22 PM Filesize: 63128 Attributes: archive MD5: F17B2B264072B921FC66A0BE16626BAB CRC32: 5184CFEA Version: 7.0.7.142 {4D25F921-B9FE-4682-BF72-8AB8210D6D75} () location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: description: MyWay Search Assistant for Dell computers classification: Legitimate known filename: %ProgramFiles%\MYWAY\SASRCHASDE1.BINDESRCAS.DLL info link: info source: TonyKlein Path: C:\Program Files\MyWaySA\SrchAsDe\1.bin\ Long name: deSrcAs.dll Short name: Date (created): 12/23/2004 7:07:00 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 9/27/2004 6:57:06 PM Filesize: 90112 Attributes: archive MD5: 1022E0D14EDCABC234FD055390C0FB01 CRC32: B056B331 Version: 1.0.1.7 {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Spybot-S&D IE Protection description: Spybot-S&D IE Browser plugin classification: Legitimate known filename: SDhelper.dll info link: http://spybot.eon.net.au/ info source: Patrick M.

Kolla Path: C:\PROGRA~1\SPYBOT~1\ Long name: SDHelper.dll Short name: Date (created): 7/17/2006 4:00:54 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 1/28/2008 11:43:28 AM Filesize: 1554256 Attributes: archive MD5: 5248E02EFBCB64D328647CD00E384B85 CRC32: C1B426A9 Version: 1.5.0.11 {5CA3D70E-1895-11CF-8E15-001234567890} (DriveLetterAccess) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: DriveLetterAccess description: Hewlett-Packard's DLA software classification: Unknown known filename: tfswshx.dll info link: info source: TonyKlein Path: C:\WINDOWS\system32\dla\ Long name: tfswshx.dll Short name: Date (created): 12/23/2004 7:05:58 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 8/13/2004 12:05:00 AM Filesize: 118842 Attributes: archive MD5: 14EFF6496CF0E873F8F7CD930B135CF9 CRC32: AD5180E4 Version: 1.4.8.0 {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: SSVHelper Class Path: C:\Program Files\Java\jre1.6.0_05\bin\ Long name: ssv.dll Short name: Date (created): 3/5/2008 9:42:48 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 2/22/2008 5:25:20 AM Filesize: 509328 Attributes: archive MD5: 5B42CB6A121256465B251840FDB1B2FE CRC32: 6EF0BCE9 Version: 6.0.50.13 {AE7CD045-E861-484f-8273-0445EE161910} (Adobe PDF Conversion Toolbar Helper) location: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ BHO name: CLSID name: Adobe PDF Conversion Toolbar Helper description: Adobe Acrobat classification: Legitimate known filename: AcroIEFavClient.dll info link: http://www.adobe.com/products/acrobatpro/main.html info source: TonyKlein Path: C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\ Long name: AcroIEFavClient.dll Short name: ACROIE~1.DLL Date (created): 9/23/2005 10:41:42 PM Date (last access): 6/23/2008 10:07:56 AM Date (last write): 9/23/2005 10:41:42 PM Filesize: 231160 Attributes: archive MD5: 6A95C44FFF0AFE30351CBC92CF327924 CRC32: 8A33F35E Version: 7.0.5.172 --- ActiveX list --- {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) DPF name: CLSID name: Office Update Installation Engine Installer: C:\WINDOWS\Downloaded Program Files\opuc.inf Codebase: http://office.microsoft.com/officeup...tent/opuc3.cab description: classification: Legitimate known filename: opuc.dll info link: info source: Safer Networking Ltd. Path: C:\WINDOWS\ Long name: opuc.dll Short name: Date (created): 11/17/2005 11:12:26 PM Date (last access): 6/23/2008 10:21:34 AM Date (last write): 11/17/2005 11:12:26 PM Filesize: 533504 Attributes: archive MD5: 24F3058766D5FC3FD0F37F6D6EE6FE9B CRC32: F1FAEDE3 Version: 12.0.3208.1014 {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_05 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M.

Kolla Path: C:\Program Files\Java\jre1.6.0_05\bin\ Long name: npjpi160_05.dll Short name: NPJPI1~1.DLL Date (created): 2/22/2008 3:33:32 AM Date (last access): 6/12/2008 2:44:52 PM Date (last write): 2/22/2008 5:25:20 AM Filesize: 132496 Attributes: archive MD5: 4FDFB86D78994BD71CBB779A7809E9CD CRC32: 5A0EB880 Version: 6.0.50.13 {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2) DPF name: Java Runtime Environment 1.4.2 CLSID name: Java Plug-in 1.4.2_03 Installer: Codebase: http://java.sun.com/products/plugin/...ndows-i586.cab description: classification: Legitimate known filename: npjpi142_03.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\j2re1.4.2_03\bin\ Long name: NPJPI142_03.dll Short name: NPJPI1~1.DLL Date (created): 11/19/2003 4:48:18 PM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 11/19/2003 4:48:12 PM Filesize: 65650 Attributes: archive MD5: 2AD31341BE41AC9B086128AD86A2B53F CRC32: 081CFB35 Version: 1.4.2.30 {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_10 Installer: Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab description: classification: Legitimate known filename: npjpi150_10.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.5.0_10\bin\ Long name: NPJPI150_10.dll Short name: NPJPI1~1.DLL Date (created): 11/9/2006 4:07:34 PM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 11/9/2006 4:21:54 PM Filesize: 75528 Attributes: archive MD5: 635F4B3A0F1C661B5CEDE628BA85E46B CRC32: 0C9B7145 Version: 5.0.100.3 {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0) DPF name: Java Runtime Environment 1.5.0 CLSID name: Java Plug-in 1.5.0_11 Installer: Codebase: http://java.sun.com/update/1.5.0/jin...ndows-i586.cab description: classification: Legitimate known filename: npjpi150_11.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.5.0_11\bin\ Long name: NPJPI150_11.dll Short name: NPJPI1~1.DLL Date (created): 12/15/2006 4:09:16 AM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 12/15/2006 4:23:26 AM Filesize: 75528 Attributes: archive MD5: 3B3F6984DBF972DAFF1B7E9C44E2FE75 CRC32: 4BDE2041 Version: 5.0.110.3 {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_01 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab description: classification: Legitimate known filename: npjpi160_01.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.6.0_01\bin\ Long name: npjpi160_01.dll Short name: NPJPI1~1.DLL Date (created): 3/14/2007 2:04:46 AM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 3/14/2007 3:43:42 AM Filesize: 132760 Attributes: archive MD5: F112FB2FD2EF66D439799E3F834DF000 CRC32: D2B09219 Version: 6.0.0.6 {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_02 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab description: classification: Legitimate known filename: npjpi160_02.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.6.0_02\bin\ Long name: npjpi160_02.dll Short name: NPJPI1~1.DLL Date (created): 7/12/2007 2:22:38 AM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 7/12/2007 4:00:36 AM Filesize: 132496 Attributes: archive MD5: E3811F1A1C5063C941EC0E2766C3EA39 CRC32: AEFD3747 Version: 6.0.20.6 {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_03 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab Path: C:\Program Files\Java\jre1.6.0_03\bin\ Long name: npjpi160_03.dll Short name: NPJPI1~1.DLL Date (created): 9/24/2007 11:31:44 PM Date (last access): 6/12/2008 2:44:54 PM Date (last write): 9/25/2007 1:11:34 AM Filesize: 132496 Attributes: archive MD5: D6A4682A6FF41832A3F1A7AB9AE08199 CRC32: 9080B537 Version: 6.0.30.5 {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_05 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab Path: C:\Program Files\Java\jre1.6.0_05\bin\ Long name: npjpi160_05.dll Short name: NPJPI1~1.DLL Date (created): 2/22/2008 3:33:32 AM Date (last access): 6/23/2008 11:04:16 AM Date (last write): 2/22/2008 5:25:20 AM Filesize: 132496 Attributes: archive MD5: 4FDFB86D78994BD71CBB779A7809E9CD CRC32: 5A0EB880 Version: 6.0.50.13 {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.6.0) DPF name: Java Runtime Environment 1.6.0 CLSID name: Java Plug-in 1.6.0_05 Installer: Codebase: http://java.sun.com/update/1.6.0/jin...ndows-i586.cab description: classification: Legitimate known filename: npjpi150_06.dll info link: info source: Safer Networking Ltd. Path: C:\Program Files\Java\jre1.6.0_05\bin\ Long name: npjpi160_05.dll Short name: NPJPI1~1.DLL Date (created): 2/22/2008 3:33:32 AM Date (last access): 6/23/2008 11:04:16 AM Date (last write): 2/22/2008 5:25:20 AM Filesize: 132496 Attributes: archive MD5: 4FDFB86D78994BD71CBB779A7809E9CD CRC32: 5A0EB880 Version: 6.0.50.13 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) DPF name: CLSID name: Shockwave Flash Object Installer: C:\WINDOWS\Downloaded Program Files\swflash.inf Codebase: http://fpdownload.macromedia.com/pub...sh/swflash.cab description: Macromedia Shockwave Flash Player classification: Legitimate known filename: info link: info source: Patrick M.

Kolla Path: C:\WINDOWS\system32\Macromed\Flash\ Long name: Flash9b.ocx Short name: Date (created): 11/9/2006 3:46:26 PM Date (last access): 6/12/2008 2:44:56 PM Date (last write): 11/9/2006 3:46:26 PM Filesize: 2262648 Attributes: readonly archive MD5: F3B3EE66CA76C94510555ABE9D00A353 CRC32: A51F3CB4 Version: 9.0.28.0 --- Process list --- PID: 0 ( 0) [System] PID: 584 ( 4) \SystemRoot\System32\smss.exe size: 50688 PID: 632 ( 584) \??\C:\WINDOWS\system32\csrss.exe size: 6144 PID: 656 ( 584) \??\C:\WINDOWS\system32\winlogon.exe size: 507904 PID: 700 ( 656) C:\WINDOWS\system32\services.exe size: 108544 MD5: 0E776ED5F7CC9F94299E70461B7B8185 PID: 712 ( 656) C:\WINDOWS\system32\lsass.exe size: 13312 MD5: BF2466B3E18E970D8A976FB95FC1CA85 PID: 888 ( 700) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 968 ( 700) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1008 ( 700) C:\WINDOWS\System32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1092 ( 700) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1188 ( 700) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1388 ( 700) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe size: 161392 MD5: 2013A368106F5EB9AA6F492369F8063C PID: 1396 (1356) C:\WINDOWS\Explorer.EXE size: 1033728 MD5: 12896823FB95BFB3DC9B46BCAEDC9923 PID: 1468 ( 700) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe size: 185968 MD5: 83053D67F40CD00D5FB3BAA2C4D6F9EC PID: 1600 ( 700) C:\WINDOWS\system32\spoolsv.exe size: 57856 MD5: D8E14A61ACC1D4A6CD0D38AEBAC7FA3B PID: 1704 ( 700) C:\Program Files\Symantec AntiVirus\DefWatch.exe size: 19648 MD5: 955924C3532EFB803B0661B6AA516126 PID: 1720 ( 700) C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe size: 942080 MD5: 7496908263A7C08DD8CCA9BADF053EE1 PID: 1764 ( 700) C:\WINDOWS\system32\imapi.exe size: 150528 MD5: 30DEAF54A9755BB8546168CFE8A6B5E1 PID: 1784 ( 700) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE size: 322120 MD5: 11F714F85530A2BD134074DC30E99FCA PID: 1900 ( 700) C:\WINDOWS\system32\svchost.exe size: 14336 MD5: 27C6D03BCDB8CFEB96B716F3D8BE3E18 PID: 1940 ( 700) C:\Program Files\Symantec AntiVirus\Rtvscan.exe size: 1706176 MD5: BC59BC3B68D45EB1716CC95E567A3B69 PID: 2036 ( 700) C:\WINDOWS\System32\wltrysvc.exe size: 45056 MD5: 84134E96E1575FBD6DCD3B7FC048587B PID: 200 (2036) C:\WINDOWS\System32\bcmwltry.exe size: 671846 MD5: A661F859C1F70BA9A9509F17AB06CCBC PID: 388 ( 700) C:\WINDOWS\system32\Tablet.exe size: 942080 MD5: E6E5A8FF39CDFED3DB3220486918D18F PID: 472 ( 388) C:\WINDOWS\system32\WTablet\TabUserW.exe size: 131072 MD5: D0CB4DA85EB71D58469227872A5A3411 PID: 628 ( 388) C:\WINDOWS\system32\Tablet.exe size: 942080 MD5: E6E5A8FF39CDFED3DB3220486918D18F PID: 1980 ( 700) C:\WINDOWS\System32\alg.exe size: 44544 MD5: 8C515081584A38AA007909CD02020B3D PID: 2176 (1396) C:\WINDOWS\system32\hkcmd.exe size: 118784 MD5: EA5DD164296F66241BEAD39E12FA69F2 PID: 2192 (1396) C:\WINDOWS\system32\dla\tfswctrl.exe size: 122939 MD5: 790490F273B0E3BCF05DC3C308ABCC0B PID: 2232 (1396) C:\Program Files\Common Files\Symantec Shared\ccApp.exe size: 48752 MD5: 696F43558EA1C4BFF475A4B8ECC5CAC4 PID: 2356 (1396) C:\PROGRA~1\SYMANT~1\VPTray.exe size: 85184 MD5: 1B5036466136A1451BDBA17B6AEBECB3 PID: 2388 (1396) C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe size: 483328 MD5: 78FF388FD58CE0BAE1F7C9670F5473C1 PID: 2400 (1396) C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe size: 144784 MD5: 836DC47E6CAD975304D1D3EB2F516A1C PID: 2408 (1396) C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe size: 53248 MD5: EFEA5551E578FF6FE52B5DB15CE13390 PID: 2416 (1396) C:\WINDOWS\system32\ctfmon.exe size: 15360 MD5: 5F1D5F88303D4A4DBC8E5F97BA967CC3 PID: 2496 (1396) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 2097488 MD5: A9A5DB6AC3721BE698B996913693D73F PID: 2740 (1396) C:\Program Files\QUICKENW\QWDLLS.EXE size: 36864 MD5: CAF57D1DCCA05A680C4E391054E6051E PID: 3084 (2424) C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe size: 103928 MD5: 1E51AE8E21C63E15E99914946C77F261 PID: 3984 (2496) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 5146448 MD5: 2ECA8CDEED7C82F879E766DA92A3561A PID: 4 ( 0) System --- Browser start & search pages list --- Spybot - Search & Destroy browser pages report, 6/23/2008 11:04:16 AM HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page C:\WINDOWS\system32\blank.htm HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page http://www.microsoft.com/isapi/redir...ie&ar=iesearch HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://www.ask.com/ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page %SystemRoot%\system32\blank.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://go.microsoft.com/fwlink/?LinkId=69157 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://go.microsoft.com/fwlink/?LinkId=69157 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://go.microsoft.com/fwlink/?LinkId=54896 HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm --- Winsock Layered Service Provider list --- Protocol 0: MSAFD Tcpip [TCP/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip[*] Protocol 1: MSAFD Tcpip [UDP/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip[*] Protocol 2: MSAFD Tcpip [RAW/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip[*] Protocol 3: RSVP UDP Service Provider GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A} Filename: %SystemRoot%\system32\rsvpsp.dll Description: Microsoft Windows NT/2k/XP RVSP DB filename: %SystemRoot%\system32\rsvpsp.dll DB protocol: RSVP * Service Provider Protocol 4: RSVP TCP Service Provider GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A} Filename: %SystemRoot%\system32\rsvpsp.dll Description: Microsoft Windows NT/2k/XP RVSP DB filename: %SystemRoot%\system32\rsvpsp.dll DB protocol: RSVP * Service Provider Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F10E9DC4-D0F8-4A98-B661-BB593B2D4E99}] SEQPACKET 6 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F10E9DC4-D0F8-4A98-B661-BB593B2D4E99}] DATAGRAM 6 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{318CF6E0-9B9F-46DB-B4C9-E38370F6F5E1}] SEQPACKET 3 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{318CF6E0-9B9F-46DB-B4C9-E38370F6F5E1}] DATAGRAM 3 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3A238661-E43B-4F83-AAE2-912E5F88A23C}] SEQPACKET 0 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3A238661-E43B-4F83-AAE2-912E5F88A23C}] DATAGRAM 0 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] SEQPACKET 1 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{2810EB22-763D-4D0C-9450-64BBD1758685}] DATAGRAM 1 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] SEQPACKET 2 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{531D3D38-B38F-4A40-9052-52EFBA55506B}] DATAGRAM 2 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D198453-C273-48ED-9B0B-7D555FF68FF6}] SEQPACKET 4 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6D198453-C273-48ED-9B0B-7D555FF68FF6}] DATAGRAM 4 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E50644F8-E2E2-440D-96A2-39FC036CF2B9}] SEQPACKET 5 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{E50644F8-E2E2-440D-96A2-39FC036CF2B9}] DATAGRAM 5 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Namespace Provider 0: Tcpip GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B} Filename: %SystemRoot%\System32\mswsock.dll Description: Microsoft Windows NT/2k/XP TCP/IP name space provider DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: TCP/IP Namespace Provider 1: NTDS GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC} Filename: %SystemRoot%\System32\winrnr.dll Description: Microsoft Windows NT/2k/XP name space provider DB filename: %SystemRoot%\system32\winrnr.dll DB protocol: NTDS Namespace Provider 2: Network Location Awareness (NLA) Namespace GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83} Filename: %SystemRoot%\System32\mswsock.dll Description: Microsoft Windows NT/2k/XP name space provider DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: NLA-Namespace --- Report generated: 2008-06-21 12:35 --- Virtumonde: [SBI $4B905FA2] User settings (Registry key, nothing done) HKEY_USERS\S-1-5-21-3293455119-3754554726-1239431001-1007\AtlMon.ReusableComp.5 --- Spybot - Search & Destroy version: 1.5.2 (build: 20080128) --- 2008-01-28 blindman.exe (1.0.0.7) 2008-01-28 SDDelFile.exe (1.0.2.4) 2008-01-28 SDMain.exe (1.0.0.5) 2007-10-07 SDShred.exe (1.0.1.2) 2008-01-28 SDUpdate.exe (1.0.8.8) 2008-01-28 SDWinSec.exe (1.0.0.11) 2008-01-28 SpybotSD.exe (1.5.2.20) 2008-01-28 TeaTimer.exe (1.5.2.16) 2006-07-17 unins000.exe (51.41.0.0) 2008-06-12 unins001.exe (51.49.0.0) 2008-01-28 Update.exe (1.4.0.6) 2008-01-28 advcheck.dll (1.5.4.5) 2007-04-02 aports.dll (2.1.0.0) 2005-05-31 borlndmm.dll (7.0.4.453) 2005-05-31 delphimm.dll (7.0.4.453) 2007-11-17 DelZip179.dll (1.79.7.4) 2008-01-28 SDFiles.dll (1.5.1.19) 2008-01-28 SDHelper.dll (1.5.0.11) 2008-01-28 Tools.dll (2.1.3.3) 2005-05-31 UnzDll.dll (1.73.1.1) 2005-05-31 ZipDll.dll (1.73.2.0) 2008-06-17 Includes\Adware.sbi (*) 2008-06-18 Includes\AdwareC.sbi (*) 2008-06-03 Includes\Cookies.sbi (*) 2008-06-03 Includes\Dialer.sbi (*) 2008-06-10 Includes\DialerC.sbi (*) 2008-06-03 Includes\HeavyDuty.sbi (*) 2008-06-16 Includes\Hijackers.sbi (*) 2008-06-17 Includes\HijackersC.sbi (*) 2008-06-03 Includes\Keyloggers.sbi (*) 2008-06-17 Includes\KeyloggersC.sbi (*) 2004-11-29 Includes\LSP.sbi (*) 2008-06-18 Includes\Malware.sbi (*) 2008-06-17 Includes\MalwareC.sbi (*) 2008-06-17 Includes\PUPS.sbi (*) 2008-06-17 Includes\PUPSC.sbi (*) 2007-11-07 Includes\Revision.sbi (*) 2008-06-10 Includes\Security.sbi (*) 2008-06-18 Includes\SecurityC.sbi (*) 2008-06-03 Includes\Spybots.sbi (*) 2008-06-03 Includes\SpybotsC.sbi (*) 2008-06-17 Includes\Spyware.sbi (*) 2008-06-17 Includes\SpywareC.sbi (*) 2008-06-03 Includes\Tracks.uti 2008-06-11 Includes\Trojans.sbi (*) 2008-06-18 Includes\TrojansC.sbi (*) 2008-03-04 Plugins\Chai.dll 2008-03-05 Plugins\Fennel.dll 2008-02-26 Plugins\Mate.dll 2007-06-06 Plugins\TCPIPAddress.dll

Hi That's great Any other issues?

Hmmmm, ran Spybot SD again this morning and it said No Immediate Threat Found.

Virtumonde can't have just disappeared?

What steps should I take to insure it has been eradicated?

Hi I recommend that you first uninstall MyWay Search assistant from add/remove programs.

After that, post back a fresh HijackThis log and I'll give you final instructions

Thank you Shaba, Removed MyWay Search Assistant as requested and here is the new HijackThis Log file.

Past few days I have been getting alerts about MyWay and am including a Spybot SD Resident Log to show you what is taking place. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2:34:29 PM, on 6/24/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\WINDOWS\system32\imapi.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\System32\wltrysvc.exe C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\WTablet\TabUserW.exe C:\WINDOWS\system32\Tablet.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\QUICKENW\QWDLLS.EXE C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\msiexec.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ask.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe" O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\Acrotray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Yahoo!

Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_0_8 -reboot 1 O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE O4 - Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ? O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: http://download.windowsupdate.com O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: TabletService - Wacom Technology, Corp.

- C:\WINDOWS\system32\Tablet.exe O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe -- End of file - 8712 bytes Resident Log Starts Here: 2008-06-21 13:53:00 Denied (based on user decision) value "AutoRun" (new data: "") deleted in Command processor! 6/21/2008 2:05:16 PM Allowed (based on user decision) value "AutoRun" (new data: "") deleted in Command processor! 2008-06-21 14:13:04 Allowed (based on user decision) value "MSMSGS" (new data: "") deleted in System Startup user entry! 2008-06-21 14:13:11 Allowed (based on user decision) value "combofix" (new data: "C:\WINDOWS\system32\CF16117.exe /c C:\ComboFix\Combobatch.bat") added in System Startup global entry! 2008-06-21 14:18:07 Allowed (based on user decision) value "combofix" (new data: "") deleted in System Startup global entry! 6/21/2008 2:35:03 PM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/21/2008 2:37:31 PM Denied (based on user decision) value "*Restore" (new data: "C:\WINDOWS\system32\restore\rstrui.exe -i") added in System Startup global entry! 6/21/2008 2:44:16 PM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/23/2008 10:14:26 AM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/23/2008 11:11:28 AM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/23/2008 11:14:30 AM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/24/2008 10:50:28 AM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/24/2008 2:28:05 PM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/24/2008 2:29:02 PM Denied (based on user decision) value "Search Bar" (new data: "http://bfc.myway.com/search/de_srchlft.html") added in Browser page! 6/24/2008 2:29:47 PM Allowed (based on user decision) value "{4D25F921-B9FE-4682-BF72-8AB8210D6D75}" (new data: "") deleted in Browser Helper Object! 6/24/2008 2:29:59 PM Denied (based on user decision) value "{4D25F926-B9FE-4682-BF72-8AB8210D6D75}" (new data: "") deleted in Internet Explorer searches!

Hi Yes, that is normal as it tries to change browser settings and TeaTimer warns about it. You can fix this, it's a leftover. R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file) Still issues left+

Due to the lack of feedback this Topic is closed. If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened.

At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. If it has been less than five days since your last response and you need the thread re-opened, please send a private message (pm).

A valid, working link to the closed topic is required. Everyone else please begin a New Topic.

Discussion Title: Virtumonde help request
Title Keywords: Virtumonde  help  request  Safer  Networking  Forums