Recently I ran into another spyware infection that was install through a security hole. It seems to be a variant of an infection that I documented about a month ago. What's new about this one is that it installs a device driver on the system, as you can see at the bottom of the FreeFixer log.
FreeFixer v0.21 log http://www.freefixer.com/ Operating system: Windows NT 5.1 Log dated 2007-06-19 15:48 System policies HKCU\..\policies\system, DisableTaskMgr = 1 (Remove) Registry Startups HKLM\..\Run, avp = C:\WINDOWS\avp.exe (Remove) HKLM\..\Run, System = C:\WINDOWS\System32\kernelwind32.exe (Remove) HKLM\..\Run, smgr = mgrs.exe (Remove) HKCU\..\Run, MSMSGS = "C:\Program\Messenger\msmsgs.exe" /background HKCU\..\Run, Windows update loader = C:\Windows\xpupdate.exe (Remove) Processes (12 whitelisted) C:\Program\Messenger\msmsgs.exe C:\Program\FreeFixer\freefixer.exe C:\WINDOWS\ftu8afna.exe (Remove) C:\WINDOWS\avp.exe (Remove) C:\WINDOWS\mgrs.exe (Remove) C:\DOCUME~1\Roger\LOKALA~1\Temp\32agent.exe (Remove) C:\DOCUME~1\Roger\LOKALA~1\Temp\power16.exe (Remove) C:\DOCUME~1\Roger\LOKALA~1\Temp\powerserver.exe (Remove) C:\Program\ucleaner_setup.exe (Remove) Drivers (26 whitelisted) Driver, , c:\windows\system32\kernelw.sys (Remove)
bill117.exe,
siszpe32.exe,
netbhl32.exe,
bill112.exe,
sshnas21.dll,
monxga32,
wwwmen32.exe,
syspck32,
zipdkg32,
monnwb32,
monnid32,
wwwpos32.exe,
aqlb.hjo,
incognito.exe,
rarype32.exe,
netuza32.exe,
9fo3ar0j.exe,
kbdsock.dll,
freddy84.exe,
freddy82.exe,
freddy81.exe,
freddy80.exe,
extrac64_cab.exe,
wmpscfgs .exe,
cliconfg64.exe,
winhlp64.exe,
siszyd32.exe,
sshnas.dll,
IS2010.exe,
smss32.exe,
winlogon32.exe,
helper32.dll,
IS15.exe,
richtx64.exe,
settdebugx.exe,
sr882388.exe,
questservice111.exe,
ccdrive32.exe,
av_md.exe,
essledv.exe,
msa.exe,
algqeh32.exe,
ld16.exe,
freddy79.exe,
photo_id.exe,
winupdate86.exe,
kwanzy131.exe,
wind7upd.exe,
mstre26.exe,
winlogon86.exe,
AVR10.exe,
webserver.exe,
ihaupd32.exe,
wyeke.exe,
wyeke.dll,
AdobeARM.exe,
WLIDSVC.EXE,
ssscheduler.exe,
getPlus_Helper.dll,
wscsvc32.exe,
zavupd32.exe,
herss.exe,
ie3sh.exe,
pp14.exe,
zwangi.exe,
msb.exe
filterpipeline..,