yes i will post ad-aware scan results right now. I seriously think my high school only has a router for protection. Against all school policies i downloaded ad-aware, i saw like 79 infections (12 were VX2 varient).
When i post the results you people will laugh This is how much our government cares for its technology. I mean jesus 79 infections. I only scanned 1 computer, ill pick another one at random tommorrow as well.
If your at a college or a high school that has poorly protected computers with infestations, download ad-aware and scan that computer, post results here! God this is really pathetic.
heres one
Ad-Aware SE Build 1.06r1
Logfile Created on:Friday, May 12, 2006 9:43:42 AM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R47 24.05.2005
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Atelys(TAC index:6):2 total references
IBIS Toolbar(TAC index:5):2 total references
JRaun(TAC index:6):4 total references
MRU List(TAC index:0):12 total references
Tracking Cookie(TAC index:3):6 total references
Windows(TAC index:3):4 total references
WinFavorites(TAC index:6):1 total references
VX2(TAC index:10):5 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
5-12-2006 9:43:42 AM - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : C:\Documents and Settings\press enter\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office
MRU List Object Recognized!
Location: : C:\Documents and Settings\press enter\recent
Description : list of recently opened documents
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d
MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X
MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw
MRU List Object Recognized!
Location: : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer
MRU List Object Recognized!
Location: : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\mediaplayer\preferences
Description : last cd record path used in microsoft windows media player
MRU List Object Recognized!
Location: : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\office\11.0\powerpoint\recentfolderlist
Description : list of recent folders used by microsoft powerpoint
MRU List Object Recognized!
Location: : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\windows\currentversion\applets\regedit
Description : last key accessed using the microsoft registry editor
MRU List Object Recognized!
Location: : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run
MRU List Object Recognized!
Location: : .DEFAULT\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
MRU List Object Recognized!
Location: : S-1-5-18\software\microsoft\windows media\wmsdk\general
Description : windows media sdk
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 2104
ThreadCreationTime : 5-12-2006 3:26:46 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : EXPLORER.EXE
#:2 [smtray.exe]
FilePath : C:\Program Files\Analog Devices\SoundMAX\
ProcessID : 2496
ThreadCreationTime : 5-12-2006 3:27:04 PM
BasePriority : Normal
FileVersion : 3, 2, 17, 0
ProductVersion : 3, 2, 0, 0
ProductName : SoundMAX Integrated Digital Audio
CompanyName : Analog Devices, Inc.
FileDescription : SoundMAX System Tray
InternalName : SMTray
LegalCopyright : Copyright © 2003 Analog Devices
OriginalFilename : SMTray.exe
#:3 [ico.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2528
ThreadCreationTime : 5-12-2006 3:27:04 PM
BasePriority : Normal
FileVersion : 1, 0, 1, 0
ProductVersion : 1.0.0.0
ProductName : MouseSuite 98
CompanyName : Primax Electronics Ltd.
FileDescription : Mouse Suite 98 Daemon
InternalName : pelmiced.exe
LegalCopyright : Copyright © 1997, Primax Electronics Ltd.
LegalTrademarks : Primax Electronics Ltd.
#:4 [fsrremos.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2536
ThreadCreationTime : 5-12-2006 3:27:04 PM
BasePriority : Normal
FileVersion : 1, 0, 0, 3
ProductVersion : 1, 0, 0, 1
ProductName : sysinf_s Application
FileDescription : sysinf_s MFC Application
InternalName : sysinf_s
LegalCopyright : Copyright © 2003
OriginalFilename : sysinf_s.EXE
#:5 [pelmiced.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2548
ThreadCreationTime : 5-12-2006 3:27:04 PM
BasePriority : Normal
FileVersion : 1, 0, 9, 9
ProductVersion : 1.0.0.0
ProductName : MouseSuite 98
CompanyName : Primax Electronics Ltd.
FileDescription : Mouse Suite 98 Daemon
InternalName : pelmiced.exe
LegalCopyright : Copyright © 1997, Primax Electronics Ltd.
LegalTrademarks : Primax Electronics Ltd.
#:6 [qttask.exe]
FilePath : C:\Program Files\QuickTime\
ProcessID : 2556
ThreadCreationTime : 5-12-2006 3:27:04 PM
BasePriority : Normal
FileVersion : 6.0.2
ProductVersion : QuickTime 6.0.2
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2002
OriginalFilename : QTTask.exe
#:7 [ccapp.exe]
FilePath : C:\Program Files\Common Files\Symantec Shared\
ProcessID : 2592
ThreadCreationTime : 5-12-2006 3:27:06 PM
BasePriority : Normal
FileVersion : 2.2.1.004
ProductVersion : 2.2.1.004
ProductName : Common Client
CompanyName : Symantec Corporation
FileDescription : Common Client User Session
InternalName : ccApp
LegalCopyright : Copyright © 2000-2003 Symantec Corporation. All rights reserved.
OriginalFilename : ccApp.exe
#:8 [vptray.exe]
FilePath : C:\PROGRA~1\SYMANT~2\
ProcessID : 2616
ThreadCreationTime : 5-12-2006 3:27:07 PM
BasePriority : Normal
FileVersion : 9.0.1.1000
ProductVersion : 9.0.1.1000
ProductName : Symantec AntiVirus
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus
LegalCopyright : Copyright 1991 - 2004 Symantec Corporation. All rights reserved.
#:9 [sboeaddon.exe]
FilePath : C:\Program Files\SpamBlockerUtility\Bin\4.7.5.0\
ProcessID : 2636
ThreadCreationTime : 5-12-2006 3:27:08 PM
BasePriority : Normal
FileVersion : 4.7.5.2500
ProductVersion : 4.7.5.2500
ProductName : SpamBlockerUtility
CompanyName : SpamBlockerUtility.com Inc.
LegalCopyright : Copyright © 2002-2005 SpamBlockerUtility.com, Inc.
LegalTrademarks : SpamBlockerUtility.com®; SpamBlockerUtility®
#:10 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2752
ThreadCreationTime : 5-12-2006 3:27:12 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE
#:11 [ad-aware.exe]
FilePath : C:\PROGRA~1\Lavasoft\AD-AWA~2\
ProcessID : 2912
ThreadCreationTime : 5-12-2006 4:42:45 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 12
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
JRaun Object Recognized!
Type : Regkey
Data :
TAC Rating : 6
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : clsid\{5c7f15e1-f31a-44fd-aa1a-2ec63aaffd3a}
JRaun Object Recognized!
Type : Regkey
Data :
TAC Rating : 6
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : speedup.speedctrl
JRaun Object Recognized!
Type : Regkey
Data :
TAC Rating : 6
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : speedup.speedctrl.1
JRaun Object Recognized!
Type : Regkey
Data :
TAC Rating : 6
Category : Malware
Comment :
Rootkey : HKEY_CLASSES_ROOT
Object : typelib\{b8ac03f2-9d1f-4d8b-a04e-6fbd1f51c109}
IBIS Toolbar Object Recognized!
Type : Regkey
Data :
TAC Rating : 5
Category : Data Miner
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\btiein
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment : Possible unwanted restriction from customizing toolbars
Rootkey : HKEY_USERS
Object : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\windows\currentversion\policies\explorer
Value : NoToolbarCustomize
Data :
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment : Possible unwanted restriction from adding/removing toolbars
Rootkey : HKEY_USERS
Object : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\windows\currentversion\policies\explorer
Value : NoBandCustomize
Data :
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment : Possible unintended lockout from Task Manager (Task manager access disabled)
Rootkey : HKEY_USERS
Object : S-1-5-21-2166734528-1295040742-3919625757-1110\software\microsoft\windows\currentversion\policies\system
Value : DisableTaskMgr
Data :
Windows Object Recognized!
Type : RegData
Data :
TAC Rating : 3
Category : Vulnerability
Comment : Manual changing of browser start-page restricted
Rootkey : HKEY_USERS
Object : S-1-5-21-2166734528-1295040742-3919625757-1110\software\policies\microsoft\internet explorer\control panel
Value : Homepage
Data :
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 9
Objects found so far: 21
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 21
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : press enter@doubleclick[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\press enter\Cookies\press enter@doubleclick[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : press enter@mediaplex[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\press enter\Cookies\press enter@mediaplex[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : press enter@stat.onestat[2].txt
TAC Rating : 3
Category : Data Miner
Comment : www.searchtraffic.com
Value : C:\Documents and Settings\press enter\Cookies\press enter@stat.onestat[2].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : setup@atdmt[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\press enter\Cookies\setup@atdmt[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : setup@ehg-foxsports.hitbox[1].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\press enter\Cookies\setup@ehg-foxsports.hitbox[1].txt
Tracking Cookie Object Recognized!
Type : IECache Entry
Data : setup@hitbox[2].txt
TAC Rating : 3
Category : Data Miner
Comment :
Value : C:\Documents and Settings\press enter\Cookies\setup@hitbox[2].txt
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 6
Objects found so far: 27
Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
VX2 Object Recognized!
Type : File
Data : alchem.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\
FileVersion : 0, 2, 1, 3
ProductVersion : 0, 2, 1, 3
CompanyName : ClickAlchemy
FileDescription : www.clickalchemy.com
LegalCopyright : Copyright © 2004
VX2 Object Recognized!
Type : File
Data : preInsBI.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\
VX2 Object Recognized!
Type : File
Data : preInsTT.exe
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\
WinFavorites Object Recognized!
Type : File
Data : a.exe
TAC Rating : 6
Category : Malware
Comment :
Object : C:\WINDOWS\system32\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
LegalCopyright : Copyright © 2003
OriginalFilename : a.exe
Atelys Object Recognized!
Type : File
Data : iexplore.exe
TAC Rating : 6
Category : Malware
Comment :
Object : C:\WINDOWS\system32\
FileVersion : 1, 0, 0, 1
ProductVersion : 1, 0, 0, 1
ProductName : Redirect Application
FileDescription : Redirect MFC Application
InternalName : Redirect
LegalCopyright : Copyright © 2003
OriginalFilename : Redirect.EXE
VX2 Object Recognized!
Type : File
Data : twaintec.dll
TAC Rating : 10
Category : Malware
Comment :
Object : C:\WINDOWS\
FileVersion : 0, 1, 4, 19
ProductVersion : 0, 1, 4, 19
ProductName : Twaintec
CompanyName : Twain Tech
FileDescription : www.twain-tech.com
InternalName : Twaintec
LegalCopyright : Copyright © 2003
OriginalFilename : Twaintec.dll
Comments : www.twain-tech.com
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 33
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
IBIS Toolbar Object Recognized!
Type : Folder
TAC Rating : 5
Category : Data Miner
Comment : IBIS Toolbar
Object : C:\Program Files\Common Files\WinTools
VX2 Object Recognized!
Type : RegValue
Data :
TAC Rating : 10
Category : Malware
Comment :
Rootkey : HKEY_CURRENT_USER
Object : software\microsoft\internet explorer\toolbar\webbrowser
Value : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Atelys Object Recognized!
Type : Regkey
Data :
TAC Rating : 6
Category : Malware
Comment :
Rootkey : HKEY_LOCAL_MACHINE
Object : software\dpcproxy
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 36
9:48:03 AM Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:04:20.763
Objects scanned:115065
Objects identified:24
Objects ignored:0
New critical objects:24
this is only for one computer, the others have more