Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > Virus/Trojan/Spyware Help > Resolved HJT Threads
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Resolved HJT Threads Resolved spyware and popup issues.

 
 
LinkBack Thread Tools
Old 03-19-2005, 05:15 PM   #1 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Cry Random problems...

Hi...

I've been having a few problems with my computer.
  • Sometimes it randomly restarts itself without warning
  • I seem to have files in my Recycle Bin (according to the desktop icon) but when entering the Bin, there's nothing there. However when I press "empty" it tells me that there are 70+ files in there
  • When on the internet, I get popups from zestyfind, xzoomy, blazefind and other randoms. I was advised to download Opera, but that only lets all the popups actually finish loading. Previously most would have to be stopped manually by my PC Gate
  • When running AdAware/Spybot, (I can't remember which) I get CnsMin coming up, but apparantly it's part of the system so I don't delete it
I'm using XP, and I think SP2 as well. I'm not sure but I think the non-popup problems started after I installed SP2. I did wonder whether uninstalling would work, but I wanted to ask some opinions first...

Anyway, here's my HijackThis! log... (should I get a newer version?)

Quote:
Logfile of HijackThis v1.98.2
Scan saved at 17:59:23, on 2004/12/12
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\system32\NTMETER.EXE
C:\Smdata\ReadSctService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\necmfk\necmfk.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\LiquidView\lviewj.exe
C:\WINDOWS\System32\hfsmop.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\PCGATE Personal\pcgate.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\子画面設定ユーティリティ\piputil.exe
C:\Program Files\Yahoo_BB\bin\mpbtn.exe
C:\WINDOWS\System32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Grisoft\AVG Free\avgcc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Program Files\BitTorrent\btdownloadgui.exe
C:\Documents and Settings\Owner\My Documents\Video Installers\HijackThis.exe

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: ラジオ(&R) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SHRunOnce] C:\Program Files\SmartHobby\SHRunOnce.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [HFSMOP] C:\WINDOWS\System32\hfsmop.exe
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SearchM] C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearc...p=ZNxmk29486JP
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: BIGLOBE:ニュース検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_news.htm
O8 - Extra context menu item: BIGLOBE:ページ検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_web.htm
O8 - Extra context menu item: BIGLOBE:画像検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_pict.htm
O8 - Extra context menu item: BIGLOBE:辞書検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_dic.htm
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: JWord(日本語キーワード) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.jword.jp/intro/?partner=A...k&frm=iebutton (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O11 - Options group: [!CNS] JWord(日本語キーワード)
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.biglobe.ne.jp/
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://fastsearchweb.com/counter/new/x.chm::/update.exe
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} -
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/sh...3/mcinsctl.cab
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) -
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} -
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} (VacPro.internazionale_ver4) - http://advnt01.com/dialer/internazionale_ver4.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/sh...20/mcgdmgr.cab
Note that this is a Japanese computer, so some of the processes mentioned are in Japanese (if you're seeing squares etc).

I have Spybot - Search and Destroy, Ad-Aware SE Personal, AVG Free and PCGATE Personal on my computer. I think the Windows Firewall that came with SP2 is active as well.

Thanks in advance...
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 03-19-2005, 06:10 PM   #2 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Please hold off on replying to this just yet... I haven't done the checks properly, and I think that's an old log. :(
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-19-2005, 11:18 PM   #3 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Seems that I can't edit the first post now... I've gone to Safe Mode and run Spybot, Ad-Aware, AVG and CWShredder before rebooting and running the Trend Micro online program. The first two found CnSMin stuff which I wasn't sure about deleting as apparantly it's part of the browser finding Asian sites (or something like that), so I didn't. Trend Micro found three bad files, which have now been deleted.

I ran HijackThis! and then ran the analyser and got this result...
Quote:
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 3/2/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 15:10:49, on 2005/03/20
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\Program Files\necmfk\necmfk.exe
C:\Program Files\LiquidView\lviewj.exe
C:\WINDOWS\System32\hfsmop.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\WINDOWS\system32\NTMETER.EXE
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Smdata\ReadSctService.exe
C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jucheck.exe
C:\Program Files\子画面設定ユーティリティ\piputil.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Yahoo_BB\bin\mpbtn.exe
C:\Program Files\PCGATE Personal\pcgate.exe

O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
O4 - HKLM\..\Run: [SHRunOnce] C:\Program Files\SmartHobby\SHRunOnce.exe
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe
O4 - HKLM\..\Run: [HFSMOP] C:\WINDOWS\System32\hfsmop.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKCU\..\Run: [SearchM] C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
O8 - Extra context menu item: BIGLOBE:ニュース検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_news.htm
O8 - Extra context menu item: BIGLOBE:ページ検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_web.htm
O8 - Extra context menu item: BIGLOBE:画像検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_pict.htm
O8 - Extra context menu item: BIGLOBE:辞書検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_dic.htm
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: JWord(日本語キーワード) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.jword.jp/intro/?partner=A...k&frm=iebutton (file missing)
O11 - Options group: [!CNS] JWord(日本語キーワード)
O14 - IERESET.INF: START_PAGE_URL=http://www.biglobe.ne.jp/
O15 - Trusted IP range: 206.161.125.149
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://fastsearchweb.com/counter/new/x.chm::/update.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...3/mcinsctl.cab
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (ウイルスバスター On-Line Scan) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} -
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} - http://advnt01.com/dialer/internazionale_ver4.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...20/mcgdmgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NT Meter - Unknown owner - C:\WINDOWS\system32\NTMETER.EXE
O23 - Service: BroadPass Manager (Poling_Service) - 日本電気株式会社 - c:\Program Files\BIGLOBE\BroadPass\base\base.exe
O23 - Service: ReadSector (ReadSctService) - Unknown owner - C:\Smdata\ReadSctService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


End of KRC HijackThis Analyzer Log.
====================================================================
All other information about this computer that I could think about adding is in the first post.
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-20-2005, 03:44 PM   #4 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

What happened here? Did someone provide a fix for you? You had a serious infection there in your initial log, but I don't see it now in your second log.

Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should not have any open browsers when you are following the procedures below.

Go to My Computer->Tools/View->Folder Options->View tab and make sure that 'Show hidden files and folders' (or 'Show all files') is enabled. Also make sure that 'Display the contents of system folders' is checked. Windows XP's search feature is a little different. When you click on 'All files and folders' on the left pane, click on the 'More advanced options' at the bottom. Make sure that Search system folders, Search hidden files and folders, and Search subfolders are checked.

For the options that you checked/enabled earlier, you may uncheck them after your log is clean. If we ask you to fix a program that you use or want to keep, please post back saying that (we don't know every program that exists, so we may tell you to delete a program that we think is bad to keep).

Turn off system restore by right clicking on My Computer and go to Properties->System Restore and check the box for Turn off System Restore. Click Apply and then OK. Restart your computer. After we are finished with your log file and verified that it's clean, you may turn it back on and create a new restore point.

Reboot into Safe Mode (hit F8 key until menu shows up). Make sure to close any open browsers. Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):

C:\WINDOWS\system32\conime.exe

Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):

O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O15 - Trusted IP range: 206.161.125.149
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone (HKLM)
O16 - DPF: {11212111-2121-1311-1141-115611111222} - ms-its:mhtml:file://d: oo.mht!http://fastsearchweb.com/counter/new/x.chm::/update.exe
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} -
O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} -
O16 - DPF: {9E98E84C-79E1-49C3-82EB-798FCD552EFB} - http://advnt01.com/dialer/internazionale_ver4.CAB

Delete the following Files/Folders (delete folders if no filename is specified) according to their directory (if none, just do a search for them) and delete them if they exist:

C:\WINDOWS\system32\conime.exe

Reboot into Normal Mode and run new HijackThis scan. If there were some entries that didn't show up in Safe Mode, you may check and fix those that appear now in normal mode (if you do that, make sure to run a new scan again). Save the log file and run KRC HijackThis Analyzer in the same folder to get the result.txt log. Just post the contents of the result.txt file in the forum.

I couldn't find much information on these:

C:\WINDOWS\System32\hfsmop.exe
C:\Program Files\????????????\piputil.exe
O4 - HKLM\..\Run: [HFSMOP] C:\WINDOWS\System32\hfsmop.exe


Do you know what they are for? If not, right click on that jfsmop.exe file and go to Properties->View to see what information you can get there.

Do this now:

Before doing anything, MAKE SURE that you can keep your computer on (at least until we get it fixed). This infection requires us to detect and remove it without rebooting or restarting your computer (unless the instructions say so). If you can't keep your computer on today, then I suggest that you don't get the logs yet until you are ready. With that said (when ready):

Please download the following programs required for the removal process:

Kill2Me http://www.greyknight17.com/spy/Kill2Me.exe
PV http://www.greyknight17.com/spy/pv.zip
VX2Finder(126) http://www.greyknight17.com/spy/VX2Finder(126).exe
Hoster http://www.greyknight17.com/spy/Hoster.exe
CleanUp! http://cleanup.stevengould.org/ or http://www.greyknight17.com/spy/Cleanup.exe
KillBox http://www.greyknight17.com/spy/KillBox.exe
notify.bat - right click on this link http://www.greyknight17.com/spy/notify.bat and choose Save As...Save it.

Please follow the steps below:

1. Download/run the following uninstallers:

Look2Me Uninstaller http://www.look2me.com/cgi-bin/UnInstaller
IGN Keyword Uninstaller http://www.greyknight17.com/spy/NLNUninstall.zip
ClearSearch Uninstaller http://www.greyknight17.com/spy/ClrSchUninstall.zip

2. Run Kill2Me.

3. Unzip the pv.zip files contents to your Desktop (NOTE: It MUST be on your Desktop!).
a) Open that folder on your Desktop and double click on the runme.bat file.
b) Type in 3 and hit your Enter key. Save the log file.
c) Type in 5 and hit your Enter key. Save the log file.
d) Remember to copy and paste both of these log files in the forum AFTER you are finished with the rest of the steps below.

4. Run notify.bat and it should open up a notify.txt Notepad file. Copy and paste this in the forum later.

5. Run VX2Finder(126) and click on the Find VX2.BetterInternet button. Click Make Log and post this in the forum later.

We also need a list of files in the following folders:

C:\WINDOWS\Downloaded Program Files\ - for these files, if they just have numbers as the filename, right click on them and go to Properties to see what they are. Post the description for each of those here.
C:\Program Files\Internet Explorer\ - there might be a download folder here. We are looking for any randomly named files. Post anything that looks suspicious.

Post all of the logs in your next post. We need them all to get a fix for this infection.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-20-2005, 05:29 PM   #5 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

The computer's been off since I posted that second log in the forum, and the next time I'll be definately be able to keep the computer on isn't for a couple of days. Is that going to affect anything?

It seems the first log was really old, as it says that I was running SP1. I do have a yellow shield (something new since I got SP2) in the taskbar telling me to install something (I think). It's in Japanese so I can't exactly tell what it is. Should I download it now or wait until this infection is cleared up?

One more thing... what infection(s) does the computer have and what is its function?
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-20-2005, 09:31 PM   #6 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

Yes, that shield is for Microsoft update. You should not have installed SP2 yet. You need to remove this infection first because Microsoft will start acting up if SP2 is installed on a unstable system (like you have right now).

You have the iGetNet infection. Look2Me might be here also. So you will need to run those programs we asked previously (hold on to the others that you didn't use yet, we'll use them later).
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-20-2005, 09:51 PM   #7 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Understood... I heard that it's possible to uninstall SP2, would that be any help?

When I get a chance (hopefully later today) I'll do all the instructions you outlined in one go. That is, unless you post again before I start telling me to only go up to a certain spot.
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-20-2005, 10:02 PM   #8 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

If it's not giving you problems, I would leave it for now. If you want to keep it for now, my suggestion is to reinstall it when all of this is done. Or if you want, revert back to SP1 now and do the fixes.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-21-2005, 05:22 AM   #9 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

It doesn't seem to be giving me any obvious problems, but which would you do? Get the fixes done now or revert to SP1 and stabilise the system before reinstalling SP2?

If it's the latter, how do I do it?
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-21-2005, 07:17 PM   #10 (permalink)
Knower of all that is MS
 
CTSNKY's Avatar
 
Join Date: Aug 2004
Posts: 10,755
OS: (multiple machines) 95, 98, 2K & XP Home & Pro


Since SP2 is already installed, I would recommend proceeding with his instructions, as provided.
__________________


GO BIG BLUE!!
CTSNKY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-25-2005, 03:56 AM   #11 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Finally able to keep the computer on, I hope you all aren't asleep ...
Quote:
Originally Posted by HijackThis Analyzer
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 3/2/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 19:21:09, on 2005/03/25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\NTMETER.EXE
C:\Smdata\ReadSctService.exe
C:\Program Files\necmfk\necmfk.exe
C:\Program Files\LiquidView\lviewj.exe
C:\WINDOWS\System32\hfsmop.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
C:\Program Files\子画面設定ユーティリティ\piputil.exe
C:\WINDOWS\system32\conime.exe
C:\Program Files\Yahoo_BB\bin\mpbtn.exe
C:\Program Files\Opera\opera.exe
C:\Program Files\PCGATE Personal\pcgate.exe

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
O4 - HKLM\..\Run: [SHRunOnce] C:\Program Files\SmartHobby\SHRunOnce.exe
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe
O4 - HKLM\..\Run: [HFSMOP] C:\WINDOWS\System32\hfsmop.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKCU\..\Run: [SearchM] C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
O8 - Extra context menu item: BIGLOBE:ニュース検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_news.htm
O8 - Extra context menu item: BIGLOBE:ページ検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_web.htm
O8 - Extra context menu item: BIGLOBE:画像検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_pict.htm
O8 - Extra context menu item: BIGLOBE:辞書検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_dic.htm
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: JWord(日本語キーワード) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.jword.jp/intro/?partner=A...k&frm=iebutton (file missing)
O11 - Options group: [!CNS] JWord(日本語キーワード)
O14 - IERESET.INF: START_PAGE_URL=http://www.biglobe.ne.jp/
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...3/mcinsctl.cab
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (ウイルスバスター On-Line Scan) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...20/mcgdmgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O18 - Protocol: about - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol hijack: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D}
O18 - Protocol hijack: file - {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B}
O18 - Protocol hijack: ftp - {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B}
O18 - Protocol hijack: http - {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B}
O18 - Protocol hijack: its - {9D148291-B9C8-11D0-A4CC-0000F80149F6}
O18 - Protocol: javascript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mailto - {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol: mhtml - {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\WINDOWS\System32\inetcomm.dll
O18 - Protocol hijack: mk - {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B}
O18 - Protocol: msdaipp - (no CLSID) - (no file)
O18 - Protocol hijack: res - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B}
O18 - Protocol: sysimage - {76E67A63-06E9-11D2-A840-006008059382} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol hijack: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E}
O18 - Protocol: vbscript - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\WINDOWS\System32\mshtml.dll
O18 - Protocol hijack: wia - {13F3EA8B-91D7-4F0A-AD76-D2853AC8BECE}
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NT Meter - Unknown owner - C:\WINDOWS\system32\NTMETER.EXE
O23 - Service: BroadPass Manager (Poling_Service) - 日本電気株式会社 - c:\Program Files\BIGLOBE\BroadPass\base\base.exe
O23 - Service: ReadSector (ReadSctService) - Unknown owner - C:\Smdata\ReadSctService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


End of KRC HijackThis Analyzer Log.
====================================================================
hfsmop.exe = NEC Half-Screen Style Utility... I think it's the thing that lets me watch TV and the computer screen at the same time.
piputil seems to be the program it uses.

Look2Me Uninstaller: No version found to uninstall, could it be because I started using Opera and haven't run IE for almost a week now?

IGN Keyword Uninstaller and ClearSearch Uninstaller said to reboot the computer, but I haven't done it yet... should I do so now?
Quote:
Originally Posted by pv.zip Log 3
It was empty
Quote:
Originally Posted by pv.zip Log 5
Module information for 'winlogon.exe'
MODULE BASE SIZE PATH
winlogon.exe 1000000 512000 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Logon Application
ntdll.dll 7c940000 643072 C:\WINDOWS\system32\ntdll.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) NT Layer DLL
kernel32.dll 7c800000 1249280 C:\WINDOWS\system32\kernel32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT BASE API Client DLL
ADVAPI32.dll 77d80000 692224 C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Advanced Windows 32 Base API
RPCRT4.dll 77e30000 593920 C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Remote Procedure Call Runtime
AUTHZ.dll 77c20000 69632 C:\WINDOWS\system32\AUTHZ.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Authorization Framework
msvcrt.dll 77bc0000 360448 C:\WINDOWS\system32\msvcrt.dll 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT CRT DLL
CRYPT32.dll 765c0000 602112 C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto API32
USER32.dll 77cf0000 585728 C:\WINDOWS\system32\USER32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP USER API Client DLL
GDI32.dll 77ed0000 286720 C:\WINDOWS\system32\GDI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) GDI Client DLL
MSASN1.dll 77c40000 73728 C:\WINDOWS\system32\MSASN1.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ASN.1 Runtime APIs
NDdeApi.dll 75880000 32768 C:\WINDOWS\system32\NDdeApi.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Network DDE Share Management APIs
PROFMAP.dll 75870000 40960 C:\WINDOWS\system32\PROFMAP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv
NETAPI32.dll 59250000 344064 C:\WINDOWS\system32\NETAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Net Win32 API DLL
USERENV.dll 759b0000 720896 C:\WINDOWS\system32\USERENV.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv
PSAPI.DLL 76ba0000 45056 C:\WINDOWS\system32\PSAPI.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Process Status Helper
REGAPI.dll 76b70000 61440 C:\WINDOWS\system32\REGAPI.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Registry Configuration APIs
Secur32.dll 77fa0000 69632 C:\WINDOWS\system32\Secur32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Security Support Provider Interface
SETUPAPI.dll 76040000 1413120 C:\WINDOWS\system32\SETUPAPI.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Setup API
VERSION.dll 77bb0000 32768 C:\WINDOWS\system32\VERSION.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Version Checking and File Installation Libraries
WINSTA.dll 762b0000 65536 C:\WINDOWS\system32\WINSTA.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Winstation Library
WINTRUST.dll 76be0000 188416 C:\WINDOWS\system32\WINTRUST.dll 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Trust Verification APIs
IMAGEHLP.dll 76c40000 163840 C:\WINDOWS\system32\IMAGEHLP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Image Helper
WS2_32.dll 719e0000 94208 C:\WINDOWS\system32\WS2_32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 32-Bit DLL
WS2HELP.dll 719d0000 32768 C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 Helper for Windows NT
IMM32.DLL 762e0000 118784 C:\WINDOWS\system32\IMM32.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP IMM32 API Client DLL
LPK.DLL 60740000 36864 C:\WINDOWS\system32\LPK.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Language Pack
USP10.dll 73f80000 438272 C:\WINDOWS\system32\USP10.dll 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158) Uniscribe Unicode script processor
MSGINA.dll 758b0000 995328 C:\WINDOWS\system32\MSGINA.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Logon GINA DLL
SHELL32.dll 77380000 8376320 C:\WINDOWS\system32\SHELL32.dll 6.00.2900.2578 (xpsp_sp2_gdr.041130-1729) Windows Shell Common Dll
SHLWAPI.dll 77f20000 483328 C:\WINDOWS\system32\SHLWAPI.dll 6.00.2900.2573 (xpsp_sp2_gdr.041130-1729) Shell Light-weight Utility Library
COMCTL32.dll 5ab60000 618496 C:\WINDOWS\system32\COMCTL32.dll 5.82 (xpsp_sp2_rtm.040803-2158) Common Controls Library
ODBC32.dll 73520000 249856 C:\WINDOWS\system32\ODBC32.dll 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) Microsoft Data Access - ODBC Driver Manager
comdlg32.dll 76300000 294912 C:\WINDOWS\system32\comdlg32.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Common Dialogs DLL
comctl32.dll 77160000 1056768 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll 6.0 (xpsp_sp2_rtm.040803-2158) User Experience Controls Library
odbcint.dll 20000000 94208 C:\WINDOWS\system32\odbcint.dll 3.525.1117.0 built by: (_sqlbld) Microsoft Data Access - ODBC Resources
SHSVCS.dll 76df0000 143360 C:\WINDOWS\system32\SHSVCS.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Windows Shell Services Dll
sfc.dll 76b60000 20480 C:\WINDOWS\system32\sfc.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows File Protection
sfc_os.dll 76c10000 167936 C:\WINDOWS\system32\sfc_os.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows File Protection
ole32.dll 76970000 1298432 C:\WINDOWS\system32\ole32.dll 5.1.2600.2595 (xpsp_sp2_gdr.041130-1729) Microsoft OLE for Windows
Apphelp.dll 76d90000 139264 C:\WINDOWS\system32\Apphelp.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Application Compatibility Client Library
msctfime.ime 73620000 188416 C:\WINDOWS\system32\msctfime.ime 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Text Frame Work Service IME
uxtheme.dll 58730000 229376 C:\WINDOWS\system32\uxtheme.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Microsoft UxTheme Library
WINSCARD.DLL 72340000 110592 C:\WINDOWS\system32\WINSCARD.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Smart Card API
WTSAPI32.dll 76f00000 32768 C:\WINDOWS\system32\WTSAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Terminal Server SDK APIs
WINMM.dll 76af0000 176128 C:\WINDOWS\system32\WINMM.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) MCI API DLL
SYNCOR11.DLL 6bd00000 53248 C:\WINDOWS\system32\SYNCOR11.DLL 1.2.3 SynthCore R2.0 Midi Interface Driver
cscdll.dll 76550000 114688 C:\WINDOWS\system32\cscdll.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Offline Network Agent
WlNotify.dll 75890000 106496 C:\WINDOWS\system32\WlNotify.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Common DLL to receive Winlogon notifications
WINSPOOL.DRV 72f50000 155648 C:\WINDOWS\system32\WINSPOOL.DRV 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Spooler Driver
MPR.dll 71a50000 73728 C:\WINDOWS\system32\MPR.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Multiple Provider Router DLL
rsaenh.dll ffd0000 163840 C:\WINDOWS\system32\rsaenh.dll 5.1.2600.2161 (xpsp.040706-1629) Microsoft Enhanced Cryptographic Provider
SAMLIB.dll 71b40000 77824 C:\WINDOWS\system32\SAMLIB.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) SAM Library DLL
sxs.dll 75de0000 716800 C:\WINDOWS\system32\sxs.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Fusion 2.5
msv1_0.dll 77cb0000 143360 C:\WINDOWS\system32\msv1_0.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Authentication Package v1.0
iphlpapi.dll 76d10000 102400 C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) IP Helper API
imjp81.ime 4edc0000 352256 C:\WINDOWS\system32\imjp81.ime 8.1.4202.0 Microsoft IME Standard
imjp81k.dll 648f0000 851968 C:\WINDOWS\system32\imjp81k.dll 8.1.4202.0 Microsoft IME
cscui.dll 76570000 327680 C:\WINDOWS\system32\cscui.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Client Side Caching UI
xpsp2res.dll 1c60000 5636096 C:\WINDOWS\system32\xpsp2res.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Service Pack 2 Messages
COMRes.dll 77000000 700416 C:\WINDOWS\system32\COMRes.dll 2001.12.4414.258
OLEAUT32.dll 770d0000 573440 C:\WINDOWS\system32\OLEAUT32.dll 5.1.2600.2180
CLBCATQ.DLL 76f80000 520192 C:\WINDOWS\system32\CLBCATQ.DLL 2001.12.4414.258
NTMARTA.DLL 76c90000 131072 C:\WINDOWS\system32\NTMARTA.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT MARTA provider
WLDAP32.dll 76f10000 180224 C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Win32 LDAP API DLL
IMJPCD.DIC 3b100000 110592 C:\WINDOWS\IME\IMJP8_1\Dicts\IMJPCD.DIC 8.1.4202.0 Microsoft IME Code Dictionary
wdmaud.drv 72c70000 36864 C:\WINDOWS\system32\wdmaud.drv 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) WDM Audio driver mapper
msacm32.drv 72c60000 32768 C:\WINDOWS\system32\msacm32.drv 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper
MSACM32.dll 77b90000 86016 C:\WINDOWS\system32\MSACM32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft ACM Audio Filter
midimap.dll 77b80000 28672 C:\WINDOWS\system32\midimap.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft MIDI Mapper
Quote:
Originally Posted by Notify
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
VX2Finder(126): When I clicked "Make Log" nothing noticable happened, so I clicked "Hosts Log" and this came up...
Quote:
Originally Posted by Hosts Log
127.0.0.1 www.igetnet.com
127.0.0.1 code.ignphrases.com
127.0.0.1 clear-search.com
127.0.0.1 r1.clrsch.com
127.0.0.1 sds.clrsch.com
127.0.0.1 status.clrsch.com
127.0.0.1 www.clrsch.com
127.0.0.1 clr-sch.com
127.0.0.1 sds-qckads.com
127.0.0.1 status.qckads.com
# Start of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
Downloaded Program Files (Description in brackets):
  • {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
  • {BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
  • FileSharingCtrl Class (fsmsngr Module)
  • Java Runtime Environment 1.4.2
  • Java Runtime Environment 1.4.2
  • MessengerStatsClient Class
  • MsnMessengerSetupDownloadControl Class
  • Solitaire Showdown Class
  • ウイルスバスター On-line Scan
The first two didn't have a description, but on the first tab the piece of information above the (install?) date was (ActiveX コントロール) the last word means "control" in Japanese. The On-Line Scan one I think says something like Wills Buster. It's the first word I'm not sure of...

C:\Program Files\Internet Explorer\
  • Folders
    • Connection Wizard
    • Custom
    • mui
    • PLUGINS
    • SIGNUP
    dll files
    • hmmapi.dll
    Applications
    • iedw (Apparantly it's Crash Detection)
    • iexplore (Internet Explorer)
    Crypto Shell Extensions
    • KB870669
    • Q330994
    • Q818529
    • Q822925
    • Q823353
    • Q831167
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-25-2005, 10:06 AM   #12 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

Go into HijackThis->Config->Misc. Tools->Open process manager. Select the following and click Kill process for each one if they are still listed (they shouldn't be - but double check it):

C:\WINDOWS\system32\conime.exe

Delete this file:

C:\WINDOWS\system32\conime.exe


Download L2MFix from one of these two locations:

http://www.atribune.org/downloads/l2mfix.exe
http://www.downloads.subratam.org/l2mfix.exe

Save the file to your desktop and double click l2mfix.exe. Click the Install button to extract the files and follow the prompts. Then open the newly added l2mfix folder on your desktop. Double click l2mfix.bat and select option #1 for Run Find Log by typing 1 and then pressing Enter. This will scan your computer and it may appear nothing is happening. After a minute or 2, notepad will open with a log. Copy the contents of that log and paste it into this thread.

IMPORTANT: Do NOT run option #2 or any other files in the l2mfix folder until you are asked to do so!
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-25-2005, 05:08 PM   #13 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Here it is... I got a popup twice that mentioned autoexec.bat but it thought that pressing yes would stop the scan, so I pressed no. I hope that was the right thing.
Quote:
Originally Posted by Report
L2MFIX find log 1.03
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{EAAC9F5A-3F4A-19DC-DBCD-B22460B7825F}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="マルチメディア ファイル プロパティ シート"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM スキャナの管理"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS セキュリティ ページ"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE ドキュメントのプロパティ ファイル"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="共有用シェル拡張"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="ディスプレイ アダプタ CPL 拡張"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="ディスプレイ モニタ CPL 拡張"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="ディスプレイ パン CPL 拡張"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="互換性のページ"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="スクラップ データ ハンドラ"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="ディスク コピー"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Microsoft Windows Network オブジェクト用シェル拡張"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM モニタの管理"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM プリンタの管理"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="ファイル圧縮用のシェル拡張"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web プリンタ シェル拡張"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="暗号化コンテキスト メニュー"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="ブリーフケース"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="フォント"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="プリンタ セキュリティ ページ"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="共有用シェル拡張"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="ネットワーク接続"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="ネットワーク接続"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="スキャナとカメラ"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="スキャナとカメラ"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="スキャナとカメラ"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="スキャナとカメラ"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="スキャナとカメラ"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Windows スクリプト ホスト用シェル拡張"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft データ リンク"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="タスク"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="タスク バーと [スタート] メニュー"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="検索"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="ヘルプとサポート"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="ヘルプとサポート"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="ファイル名を指定して実行..."
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="インターネット"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="電子メール"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="フォント"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="管理ツール"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="アドレス(&A)"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="履歴"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="インターネット一時ファイル"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="インターネット一時ファイル"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite スプラッシュ画面"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="インターネット"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX キャッシュ フォルダ"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="購読のフォルダ"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web 発行ウィザード"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Web でプリントを注文"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Passport 取得ウィザード"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="ユーザー アカウント"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="チャンネル ファイル"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="チャンネル ショートカット"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="チャンネル ハンドラ オプジェクト"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="オフライン ファイル フォルダ"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="人(&P)..."
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{AB314ECE-27C9-4703-8891-38914A228711}"="Liquid Surf Explore Hook"
"{CC1DC91A-F90E-4906-B40E-FA1811DE4EFF}"="Liquid Surf View"
"{B9F633F6-EA44-45F4-91EB-FABFC65A0634}"="&Liquid Surf"
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
"{BDEADF00-C265-11D0-BCED-00A0C90AB50F}"="Web Folders"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{42042206-2D85-11D3-8CFF-005004838597}"="Microsoft Office HTML Icon Handler"
"{20090439-D041-4A68-A8F0-74AEA45FE3F3}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}"=""
"{1D2680C9-0E2A-469d-B787-065558BC7D43}"="Fusion Cache"
"{A77FE05B-AD26-49B9-89E0-501CCAF601FF}"=""
"{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}"=""

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{20090439-D041-4A68-A8F0-74AEA45FE3F3}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20090439-D041-4A68-A8F0-74AEA45FE3F3}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{20090439-D041-4A68-A8F0-74AEA45FE3F3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{A77FE05B-AD26-49B9-89E0-501CCAF601FF}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A77FE05B-AD26-49B9-89E0-501CCAF601FF}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{A77FE05B-AD26-49B9-89E0-501CCAF601FF}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

**********************************************************************************
Files Found are not all bad files:
Locate .tmp files:
**********************************************************************************
Directory Listing of system files:
ドライブ C のボリューム ラベルは Windows XP です
ボリューム シリアル番号は 1C52-84C3 です

C:\WINDOWS\System32 のディレクトリ

2005/03/20 13:00 234,447 guard.tmp
2005/03/20 08:25 233,248 n28o0cl3efq.dll
2005/03/16 22:00 0 e6202gfmg62a2.dll
2005/03/16 22:00 233,248 DkvXc32.dll
2005/03/16 21:59 233,248 ddrgsnap.dll
2005/03/15 23:05 232,736 l6p2lg7o16.dll
2005/03/15 22:58 232,736 irj6l51s1.dll
2005/03/15 16:41 232,736 l8l6li3s18.dll
2005/03/09 13:45 232,736 Azdiodev.dll
2005/03/09 13:44 232,736 wgaueng1.dll
2005/03/09 12:44 232,736 jSp00i7me8.dll
2005/03/09 12:44 232,736 iymontr.dll
2005/03/09 11:44 232,736 kqda1.dll
2005/03/09 11:44 232,736 iqign32.dll
2005/03/09 10:44 232,736 jVvart.dll
2005/03/09 10:44 232,736 iqmontr.dll
2005/03/09 09:44 232,736 nvsdexts.dll
2005/03/09 09:44 232,736 ndtplwiz.dll
2005/03/09 08:45 232,736 qvsname.dll
2005/03/09 08:45 0 dn2001fme.dll
2005/03/09 08:44 232,736 nflanman.dll
2005/03/09 02:51 225,118 gp00l3dm1.dll
2005/03/08 18:18 224,151 lvj8091ue.dll
2005/03/05 09:17 222,684 j8p00i7me8.dll
2005/03/02 08:57 222,606 g6040gdqe60e0.dll
2005/03/02 08:39 222,606 dn2401fqe.dll
2005/03/01 23:25 225,946 m4ls0e37eh.dll
2005/02/16 16:30 <DIR> dllcache
2005/02/15 20:20 222,832 f22mlcf11f2.dll
2005/02/15 13:37 222,356 n6r20g9oe6.dll
2005/02/15 09:30 222,590 p46s0ej7eho.dll
2005/02/14 10:40 225,264 hr6s05j7e.dll
2005/02/13 09:03 223,296 i6nmlg5116.dll
2005/02/13 08:40 223,296 en0ql1d51.dll
2005/02/12 16:36 225,125 g640lghm164a.dll
2005/02/12 14:40 225,999 h4l20e3oeh.dll
2005/02/07 22:55 223,120 h04m0ah1ed4.dll
2005/02/07 22:41 224,168 l88mlil118q.dll
2005/02/07 22:27 224,356 m6polg7316.dll
2005/02/07 21:57 222,980 mv64l9jq1.dll
2005/02/07 13:14 222,684 lv0m09d1e.dll
2005/02/03 00:28 222,684 f42m0ef1eh2.dll
2005/02/02 13:43 222,684 mv06l9ds1.dll
2005/01/31 02:20 225,469 mv80l9lm1.dll
2005/01/24 01:22 222,889 dn4m01h1e.dll
2005/01/23 08:29 224,921 f2l02c3mgf.dll
2005/01/19 10:59 222,889 enrol1931.dll
2005/01/19 10:39 222,889 lv6u09j9e.dll
2005/01/19 03:12 222,889 en46l1hs1.dll
2005/01/16 07:56 222,889 q4nule591h.dll
2005/01/16 01:48 225,224 n26q0cj5efo.dll
2005/01/12 10:58 223,231 lt4027hmg.dll
2005/01/11 23:16 224,021 q068laju1do8.dll
2005/01/07 09:31 224,693 mv28l9fu1.dll
2005/01/06 12:42 222,864 n26qlcj51fo.dll
2005/01/01 19:59 226,160 hr2805fue.dll
2004/12/31 06:07 226,098 aza00cjmefoa0.dll
2004/12/30 18:01 225,769 dn8s01l7e.dll
2004/12/25 15:57 222,942 n22u0cf9ef2.dll
2004/12/20 21:02 225,769 n8n6li5s18.dll
2004/12/20 21:00 226,004 hrl2053oe.dll
2004/12/18 11:49 222,599 r28s0cl7efq.dll
2004/12/15 18:43 224,739 t2r8lc9u1f.dll
2004/12/12 13:15 225,069 i460lejm1hoa.dll
2004/12/11 15:41 224,049 k4pmle711h.dll
2003/10/31 21:25 <DIR> Microsoft
64 個のファイル 14,055,842 バイト
2 個のディレクトリ 981,950,464 バイトの空き領域
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-26-2005, 03:33 PM   #14 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing Enter, then press any key to reboot your computer. After a reboot, your desktop and icons will appear, then disappear (this is normal). L2MFix will continue to scan your computer and when it's finished, notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!

Also give us an updated HijackThis log.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-26-2005, 04:47 PM   #15 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

I noticed the conime.exe file while doing the HijackThis scan this time and deleted it...
Quote:
Originally Posted by L2Mfix Log
L2Mfix 1.03

Running From:
C:\Documents and Settings\Owner\デスクトップ\l2mfix



RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting registry permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Denying C(CI) access for predefined group "Administrators"
- adding new ACCESS DENY entry


Registry Permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(CI) DENY --C------- BUILTIN\Administrators
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER



Setting up for Reboot


Starting Reboot!

C:\Documents and Settings\Owner\デスクトップ\l2mfix
System Rebooted!

Running From:
C:\Documents and Settings\Owner\デスクトップ\l2mfix

killing explorer and rundll32.exe

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Killing PID 1612 'explorer.exe'
Killing PID 1612 'explorer.exe'
Killing PID 1612 'explorer.exe'
Killing PID 1612 'explorer.exe'

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
Error, Cannot find a process with an image name of rundll32.exe

Scanning First Pass. Please Wait!

First Pass Completed

Second Pass Scanning

Second pass Completed!
Backing Up: C:\WINDOWS\system32\aza00cjmefoa0.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\Azdiodev.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\cartcli.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\chgmgr32.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\cqgmgr32.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\ddrgsnap.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\DkvXc32.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\dn2401fqe.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\dn4m01h1e.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\dn8s01l7e.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\dpsec.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\en0ql1d51.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\en46l1hs1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\enrol1931.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\f22mlcf11f2.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\f2l02c3mgf.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\f42m0ef1eh2.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\g6040gdqe60e0.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\g640lghm164a.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\gp00l3dm1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\h04m0ah1ed4.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\h4l20e3oeh.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\hr2805fue.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\hr6s05j7e.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\hrl2053oe.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\i460lejm1hoa.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\i6nmlg5116.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\iA60lejm1hoa.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\iqign32.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\iqmontr.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\irj6l51s1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\iymontr.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\j8p00i7me8.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\jSp00i7me8.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\jVvart.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\k4pmle711h.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\kcdpl.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\kjymgr.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\kqda1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\l6p2lg7o16.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\l88mlil118q.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\l8l6li3s18.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\liras12n.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\LQWEN12N.DLL
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\lt4027hmg.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\lv0m09d1e.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\lv6u09j9e.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\lvj8091ue.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\m4ls0e37eh.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\m6polg7316.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\mv06l9ds1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\mv28l9fu1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\mv64l9jq1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\mv80l9lm1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n22u0cf9ef2.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n26q0cj5efo.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n26qlcj51fo.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n28o0cl3efq.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n6r20g9oe6.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\n8n6li5s18.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\ndtplwiz.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\nflanman.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\nvsdexts.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\p46s0ej7eho.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\q068laju1do8.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\q4nule591h.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\qvsname.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\r28s0cl7efq.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\sansapi.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\snellstyle.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\t2r8lc9u1f.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\tprmsrv.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\wgaueng1.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\wzhjp.dll
1 個のファイルをコピーしました。
Backing Up: C:\WINDOWS\system32\guard.tmp
1 個のファイルをコピーしました。
deleting: C:\WINDOWS\system32\aza00cjmefoa0.dll
Successfully Deleted: C:\WINDOWS\system32\aza00cjmefoa0.dll
deleting: C:\WINDOWS\system32\Azdiodev.dll
Successfully Deleted: C:\WINDOWS\system32\Azdiodev.dll
deleting: C:\WINDOWS\system32\cartcli.dll
Successfully Deleted: C:\WINDOWS\system32\cartcli.dll
deleting: C:\WINDOWS\system32\chgmgr32.dll
Successfully Deleted: C:\WINDOWS\system32\chgmgr32.dll
deleting: C:\WINDOWS\system32\cqgmgr32.dll
Successfully Deleted: C:\WINDOWS\system32\cqgmgr32.dll
deleting: C:\WINDOWS\system32\ddrgsnap.dll
Successfully Deleted: C:\WINDOWS\system32\ddrgsnap.dll
deleting: C:\WINDOWS\system32\DkvXc32.dll
Successfully Deleted: C:\WINDOWS\system32\DkvXc32.dll
deleting: C:\WINDOWS\system32\dn2401fqe.dll
Successfully Deleted: C:\WINDOWS\system32\dn2401fqe.dll
deleting: C:\WINDOWS\system32\dn4m01h1e.dll
Successfully Deleted: C:\WINDOWS\system32\dn4m01h1e.dll
deleting: C:\WINDOWS\system32\dn8s01l7e.dll
Successfully Deleted: C:\WINDOWS\system32\dn8s01l7e.dll
deleting: C:\WINDOWS\system32\dpsec.dll
Successfully Deleted: C:\WINDOWS\system32\dpsec.dll
deleting: C:\WINDOWS\system32\en0ql1d51.dll
Successfully Deleted: C:\WINDOWS\system32\en0ql1d51.dll
deleting: C:\WINDOWS\system32\en46l1hs1.dll
Successfully Deleted: C:\WINDOWS\system32\en46l1hs1.dll
deleting: C:\WINDOWS\system32\enrol1931.dll
Successfully Deleted: C:\WINDOWS\system32\enrol1931.dll
deleting: C:\WINDOWS\system32\f22mlcf11f2.dll
Successfully Deleted: C:\WINDOWS\system32\f22mlcf11f2.dll
deleting: C:\WINDOWS\system32\f2l02c3mgf.dll
Successfully Deleted: C:\WINDOWS\system32\f2l02c3mgf.dll
deleting: C:\WINDOWS\system32\f42m0ef1eh2.dll
Successfully Deleted: C:\WINDOWS\system32\f42m0ef1eh2.dll
deleting: C:\WINDOWS\system32\g6040gdqe60e0.dll
Successfully Deleted: C:\WINDOWS\system32\g6040gdqe60e0.dll
deleting: C:\WINDOWS\system32\g640lghm164a.dll
Successfully Deleted: C:\WINDOWS\system32\g640lghm164a.dll
deleting: C:\WINDOWS\system32\gp00l3dm1.dll
Successfully Deleted: C:\WINDOWS\system32\gp00l3dm1.dll
deleting: C:\WINDOWS\system32\h04m0ah1ed4.dll
Successfully Deleted: C:\WINDOWS\system32\h04m0ah1ed4.dll
deleting: C:\WINDOWS\system32\h4l20e3oeh.dll
Successfully Deleted: C:\WINDOWS\system32\h4l20e3oeh.dll
deleting: C:\WINDOWS\system32\hr2805fue.dll
Successfully Deleted: C:\WINDOWS\system32\hr2805fue.dll
deleting: C:\WINDOWS\system32\hr6s05j7e.dll
Successfully Deleted: C:\WINDOWS\system32\hr6s05j7e.dll
deleting: C:\WINDOWS\system32\hrl2053oe.dll
Successfully Deleted: C:\WINDOWS\system32\hrl2053oe.dll
deleting: C:\WINDOWS\system32\i460lejm1hoa.dll
Successfully Deleted: C:\WINDOWS\system32\i460lejm1hoa.dll
deleting: C:\WINDOWS\system32\i6nmlg5116.dll
Successfully Deleted: C:\WINDOWS\system32\i6nmlg5116.dll
deleting: C:\WINDOWS\system32\iA60lejm1hoa.dll
Successfully Deleted: C:\WINDOWS\system32\iA60lejm1hoa.dll
deleting: C:\WINDOWS\system32\iqign32.dll
Successfully Deleted: C:\WINDOWS\system32\iqign32.dll
deleting: C:\WINDOWS\system32\iqmontr.dll
Successfully Deleted: C:\WINDOWS\system32\iqmontr.dll
deleting: C:\WINDOWS\system32\irj6l51s1.dll
Successfully Deleted: C:\WINDOWS\system32\irj6l51s1.dll
deleting: C:\WINDOWS\system32\iymontr.dll
Successfully Deleted: C:\WINDOWS\system32\iymontr.dll
deleting: C:\WINDOWS\system32\j8p00i7me8.dll
Successfully Deleted: C:\WINDOWS\system32\j8p00i7me8.dll
deleting: C:\WINDOWS\system32\jSp00i7me8.dll
Successfully Deleted: C:\WINDOWS\system32\jSp00i7me8.dll
deleting: C:\WINDOWS\system32\jVvart.dll
Successfully Deleted: C:\WINDOWS\system32\jVvart.dll
deleting: C:\WINDOWS\system32\k4pmle711h.dll
Successfully Deleted: C:\WINDOWS\system32\k4pmle711h.dll
deleting: C:\WINDOWS\system32\kcdpl.dll
Successfully Deleted: C:\WINDOWS\system32\kcdpl.dll
deleting: C:\WINDOWS\system32\kjymgr.dll
Successfully Deleted: C:\WINDOWS\system32\kjymgr.dll
deleting: C:\WINDOWS\system32\kqda1.dll
Successfully Deleted: C:\WINDOWS\system32\kqda1.dll
deleting: C:\WINDOWS\system32\l6p2lg7o16.dll
Successfully Deleted: C:\WINDOWS\system32\l6p2lg7o16.dll
deleting: C:\WINDOWS\system32\l88mlil118q.dll
Successfully Deleted: C:\WINDOWS\system32\l88mlil118q.dll
deleting: C:\WINDOWS\system32\l8l6li3s18.dll
Successfully Deleted: C:\WINDOWS\system32\l8l6li3s18.dll
deleting: C:\WINDOWS\system32\liras12n.dll
Successfully Deleted: C:\WINDOWS\system32\liras12n.dll
deleting: C:\WINDOWS\system32\LQWEN12N.DLL
Successfully Deleted: C:\WINDOWS\system32\LQWEN12N.DLL
deleting: C:\WINDOWS\system32\lt4027hmg.dll
Successfully Deleted: C:\WINDOWS\system32\lt4027hmg.dll
deleting: C:\WINDOWS\system32\lv0m09d1e.dll
Successfully Deleted: C:\WINDOWS\system32\lv0m09d1e.dll
deleting: C:\WINDOWS\system32\lv6u09j9e.dll
Successfully Deleted: C:\WINDOWS\system32\lv6u09j9e.dll
deleting: C:\WINDOWS\system32\lvj8091ue.dll
Successfully Deleted: C:\WINDOWS\system32\lvj8091ue.dll
deleting: C:\WINDOWS\system32\m4ls0e37eh.dll
Successfully Deleted: C:\WINDOWS\system32\m4ls0e37eh.dll
deleting: C:\WINDOWS\system32\m6polg7316.dll
Successfully Deleted: C:\WINDOWS\system32\m6polg7316.dll
deleting: C:\WINDOWS\system32\mv06l9ds1.dll
Successfully Deleted: C:\WINDOWS\system32\mv06l9ds1.dll
deleting: C:\WINDOWS\system32\mv28l9fu1.dll
Successfully Deleted: C:\WINDOWS\system32\mv28l9fu1.dll
deleting: C:\WINDOWS\system32\mv64l9jq1.dll
Successfully Deleted: C:\WINDOWS\system32\mv64l9jq1.dll
deleting: C:\WINDOWS\system32\mv80l9lm1.dll
Successfully Deleted: C:\WINDOWS\system32\mv80l9lm1.dll
deleting: C:\WINDOWS\system32\n22u0cf9ef2.dll
Successfully Deleted: C:\WINDOWS\system32\n22u0cf9ef2.dll
deleting: C:\WINDOWS\system32\n26q0cj5efo.dll
Successfully Deleted: C:\WINDOWS\system32\n26q0cj5efo.dll
deleting: C:\WINDOWS\system32\n26qlcj51fo.dll
Successfully Deleted: C:\WINDOWS\system32\n26qlcj51fo.dll
deleting: C:\WINDOWS\system32\n28o0cl3efq.dll
Successfully Deleted: C:\WINDOWS\system32\n28o0cl3efq.dll
deleting: C:\WINDOWS\system32\n6r20g9oe6.dll
Successfully Deleted: C:\WINDOWS\system32\n6r20g9oe6.dll
deleting: C:\WINDOWS\system32\n8n6li5s18.dll
Successfully Deleted: C:\WINDOWS\system32\n8n6li5s18.dll
deleting: C:\WINDOWS\system32\ndtplwiz.dll
Successfully Deleted: C:\WINDOWS\system32\ndtplwiz.dll
deleting: C:\WINDOWS\system32\nflanman.dll
Successfully Deleted: C:\WINDOWS\system32\nflanman.dll
deleting: C:\WINDOWS\system32\nvsdexts.dll
Successfully Deleted: C:\WINDOWS\system32\nvsdexts.dll
deleting: C:\WINDOWS\system32\p46s0ej7eho.dll
Successfully Deleted: C:\WINDOWS\system32\p46s0ej7eho.dll
deleting: C:\WINDOWS\system32\q068laju1do8.dll
Successfully Deleted: C:\WINDOWS\system32\q068laju1do8.dll
deleting: C:\WINDOWS\system32\q4nule591h.dll
Successfully Deleted: C:\WINDOWS\system32\q4nule591h.dll
deleting: C:\WINDOWS\system32\qvsname.dll
Successfully Deleted: C:\WINDOWS\system32\qvsname.dll
deleting: C:\WINDOWS\system32\r28s0cl7efq.dll
Successfully Deleted: C:\WINDOWS\system32\r28s0cl7efq.dll
deleting: C:\WINDOWS\system32\sansapi.dll
Successfully Deleted: C:\WINDOWS\system32\sansapi.dll
deleting: C:\WINDOWS\system32\snellstyle.dll
Successfully Deleted: C:\WINDOWS\system32\snellstyle.dll
deleting: C:\WINDOWS\system32\t2r8lc9u1f.dll
Successfully Deleted: C:\WINDOWS\system32\t2r8lc9u1f.dll
deleting: C:\WINDOWS\system32\tprmsrv.dll
Successfully Deleted: C:\WINDOWS\system32\tprmsrv.dll
deleting: C:\WINDOWS\system32\wgaueng1.dll
Successfully Deleted: C:\WINDOWS\system32\wgaueng1.dll
deleting: C:\WINDOWS\system32\wzhjp.dll
Successfully Deleted: C:\WINDOWS\system32\wzhjp.dll
deleting: C:\WINDOWS\system32\guard.tmp
Successfully Deleted: C:\WINDOWS\system32\guard.tmp

Desktop.ini sucessfully removed

Zipping up files for submission:
adding: aza00cjmefoa0.dll (164 bytes security) (deflated 5%)
adding: Azdiodev.dll (164 bytes security) (deflated 4%)
adding: cartcli.dll (164 bytes security) (deflated 3%)
adding: chgmgr32.dll (164 bytes security) (deflated 4%)
adding: cqgmgr32.dll (164 bytes security) (deflated 3%)
adding: ddrgsnap.dll (164 bytes security) (deflated 4%)
adding: DkvXc32.dll (164 bytes security) (deflated 4%)
adding: dn2401fqe.dll (164 bytes security) (deflated 3%)
adding: dn4m01h1e.dll (164 bytes security) (deflated 3%)
adding: dn8s01l7e.dll (164 bytes security) (deflated 5%)
adding: dpsec.dll (164 bytes security) (deflated 3%)
adding: en0ql1d51.dll (164 bytes security) (deflated 4%)
adding: en46l1hs1.dll (164 bytes security) (deflated 3%)
adding: enrol1931.dll (164 bytes security) (deflated 3%)
adding: f22mlcf11f2.dll (164 bytes security) (deflated 3%)
adding: f2l02c3mgf.dll (164 bytes security) (deflated 4%)
adding: f42m0ef1eh2.dll (164 bytes security) (deflated 3%)
adding: g6040gdqe60e0.dll (164 bytes security) (deflated 3%)
adding: g640lghm164a.dll (164 bytes security) (deflated 4%)
adding: gp00l3dm1.dll (164 bytes security) (deflated 4%)
adding: h04m0ah1ed4.dll (164 bytes security) (deflated 4%)
adding: h4l20e3oeh.dll (164 bytes security) (deflated 5%)
adding: hr2805fue.dll (164 bytes security) (deflated 5%)
adding: hr6s05j7e.dll (164 bytes security) (deflated 4%)
adding: hrl2053oe.dll (164 bytes security) (deflated 5%)
adding: i460lejm1hoa.dll (164 bytes security) (deflated 4%)
adding: i6nmlg5116.dll (164 bytes security) (deflated 4%)
adding: iA60lejm1hoa.dll (164 bytes security) (deflated 4%)
adding: iqign32.dll (164 bytes security) (deflated 4%)
adding: iqmontr.dll (164 bytes security) (deflated 4%)
adding: irj6l51s1.dll (164 bytes security) (deflated 4%)
adding: iymontr.dll (164 bytes security) (deflated 4%)
adding: j8p00i7me8.dll (164 bytes security) (deflated 3%)
adding: jSp00i7me8.dll (164 bytes security) (deflated 4%)
adding: jVvart.dll (164 bytes security) (deflated 4%)
adding: k4pmle711h.dll (164 bytes security) (deflated 4%)
adding: kcdpl.dll (164 bytes security) (deflated 5%)
adding: kjymgr.dll (164 bytes security) (deflated 5%)
adding: kqda1.dll (164 bytes security) (deflated 4%)
adding: l6p2lg7o16.dll (164 bytes security) (deflated 4%)
adding: l88mlil118q.dll (164 bytes security) (deflated 4%)
adding: l8l6li3s18.dll (164 bytes security) (deflated 4%)
adding: liras12n.dll (164 bytes security) (deflated 4%)
adding: LQWEN12N.DLL (164 bytes security) (deflated 4%)
adding: lt4027hmg.dll (164 bytes security) (deflated 4%)
adding: lv0m09d1e.dll (164 bytes security) (deflated 3%)
adding: lv6u09j9e.dll (164 bytes security) (deflated 3%)
adding: lvj8091ue.dll (164 bytes security) (deflated 4%)
adding: m4ls0e37eh.dll (164 bytes security) (deflated 5%)
adding: m6polg7316.dll (164 bytes security) (deflated 4%)
adding: mv06l9ds1.dll (164 bytes security) (deflated 3%)
adding: mv28l9fu1.dll (164 bytes security) (deflated 4%)
adding: mv64l9jq1.dll (164 bytes security) (deflated 4%)
adding: mv80l9lm1.dll (164 bytes security) (deflated 5%)
adding: n22u0cf9ef2.dll (164 bytes security) (deflated 3%)
adding: n26q0cj5efo.dll (164 bytes security) (deflated 4%)
adding: n26qlcj51fo.dll (164 bytes security) (deflated 3%)
adding: n28o0cl3efq.dll (164 bytes security) (deflated 4%)
adding: n6r20g9oe6.dll (164 bytes security) (deflated 3%)
adding: n8n6li5s18.dll (164 bytes security) (deflated 5%)
adding: ndtplwiz.dll (164 bytes security) (deflated 4%)
adding: nflanman.dll (164 bytes security) (deflated 4%)
adding: nvsdexts.dll (164 bytes security) (deflated 4%)
adding: p46s0ej7eho.dll (164 bytes security) (deflated 3%)
adding: q068laju1do8.dll (164 bytes security) (deflated 4%)
adding: q4nule591h.dll (164 bytes security) (deflated 3%)
adding: qvsname.dll (164 bytes security) (deflated 4%)
adding: r28s0cl7efq.dll (164 bytes security) (deflated 3%)
adding: sansapi.dll (164 bytes security) (deflated 4%)
adding: snellstyle.dll (164 bytes security) (deflated 5%)
adding: t2r8lc9u1f.dll (164 bytes security) (deflated 4%)
adding: tprmsrv.dll (164 bytes security) (deflated 4%)
adding: wgaueng1.dll (164 bytes security) (deflated 4%)
adding: wzhjp.dll (164 bytes security) (deflated 4%)
adding: guard.tmp (164 bytes security) (deflated 5%)
adding: clear.reg (164 bytes security) (deflated 51%)
adding: echo.reg (164 bytes security) (deflated 8%)
adding: desktop.ini (164 bytes security) (deflated 16%)
adding: direct.txt (164 bytes security) (stored 0%)
adding: lo2.txt (164 bytes security) (deflated 88%)
adding: readme.txt (164 bytes security) (deflated 49%)
adding: report.txt (164 bytes security) (deflated 64%)
adding: test.txt (164 bytes security) (deflated 83%)
adding: test2.txt (164 bytes security) (deflated 33%)
adding: test3.txt (164 bytes security) (deflated 33%)
adding: test5.txt (164 bytes security) (deflated 33%)
adding: xfind.txt (164 bytes security) (deflated 78%)
adding: backregs/1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A.reg (164 bytes security) (deflated 69%)
adding: backregs/20090439-D041-4A68-A8F0-74AEA45FE3F3.reg (164 bytes security) (deflated 69%)
adding: backregs/A77FE05B-AD26-49B9-89E0-501CCAF601FF.reg (164 bytes security) (deflated 69%)
adding: backregs/F7A03849-6E45-461F-A3C6-BDF6E326CA4C.reg (164 bytes security) (deflated 69%)
adding: backregs/shell.reg (164 bytes security) (deflated 71%)

Restoring Registry Permissions:


RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!


Revoking access for predefined group "Administrators"
Inherited ACE can not be revoked here!
Inherited ACE can not be revoked here!


Registry permissions set too:

RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
This program is Freeware, use it on your own risk!

Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(NI) ALLOW Full access NT AUTHORITY\SYSTEM
(IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-NI) ALLOW Read BUILTIN\Users
(ID-IO) ALLOW Read BUILTIN\Users
(ID-NI) ALLOW Full access BUILTIN\Administrators
(ID-IO) ALLOW Full access BUILTIN\Administrators
(ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
(ID-IO) ALLOW Full access CREATOR OWNER


Restoring Sedebugprivilege:

Granting SeDebugPrivilege to Administrators ... successful

deleting local copy: aza00cjmefoa0.dll
deleting local copy: Azdiodev.dll
deleting local copy: cartcli.dll
deleting local copy: chgmgr32.dll
deleting local copy: cqgmgr32.dll
deleting local copy: ddrgsnap.dll
deleting local copy: DkvXc32.dll
deleting local copy: dn2401fqe.dll
deleting local copy: dn4m01h1e.dll
deleting local copy: dn8s01l7e.dll
deleting local copy: dpsec.dll
deleting local copy: en0ql1d51.dll
deleting local copy: en46l1hs1.dll
deleting local copy: enrol1931.dll
deleting local copy: f22mlcf11f2.dll
deleting local copy: f2l02c3mgf.dll
deleting local copy: f42m0ef1eh2.dll
deleting local copy: g6040gdqe60e0.dll
deleting local copy: g640lghm164a.dll
deleting local copy: gp00l3dm1.dll
deleting local copy: h04m0ah1ed4.dll
deleting local copy: h4l20e3oeh.dll
deleting local copy: hr2805fue.dll
deleting local copy: hr6s05j7e.dll
deleting local copy: hrl2053oe.dll
deleting local copy: i460lejm1hoa.dll
deleting local copy: i6nmlg5116.dll
deleting local copy: iA60lejm1hoa.dll
deleting local copy: iqign32.dll
deleting local copy: iqmontr.dll
deleting local copy: irj6l51s1.dll
deleting local copy: iymontr.dll
deleting local copy: j8p00i7me8.dll
deleting local copy: jSp00i7me8.dll
deleting local copy: jVvart.dll
deleting local copy: k4pmle711h.dll
deleting local copy: kcdpl.dll
deleting local copy: kjymgr.dll
deleting local copy: kqda1.dll
deleting local copy: l6p2lg7o16.dll
deleting local copy: l88mlil118q.dll
deleting local copy: l8l6li3s18.dll
deleting local copy: liras12n.dll
deleting local copy: LQWEN12N.DLL
deleting local copy: lt4027hmg.dll
deleting local copy: lv0m09d1e.dll
deleting local copy: lv6u09j9e.dll
deleting local copy: lvj8091ue.dll
deleting local copy: m4ls0e37eh.dll
deleting local copy: m6polg7316.dll
deleting local copy: mv06l9ds1.dll
deleting local copy: mv28l9fu1.dll
deleting local copy: mv64l9jq1.dll
deleting local copy: mv80l9lm1.dll
deleting local copy: n22u0cf9ef2.dll
deleting local copy: n26q0cj5efo.dll
deleting local copy: n26qlcj51fo.dll
deleting local copy: n28o0cl3efq.dll
deleting local copy: n6r20g9oe6.dll
deleting local copy: n8n6li5s18.dll
deleting local copy: ndtplwiz.dll
deleting local copy: nflanman.dll
deleting local copy: nvsdexts.dll
deleting local copy: p46s0ej7eho.dll
deleting local copy: q068laju1do8.dll
deleting local copy: q4nule591h.dll
deleting local copy: qvsname.dll
deleting local copy: r28s0cl7efq.dll
deleting local copy: sansapi.dll
deleting local copy: snellstyle.dll
deleting local copy: t2r8lc9u1f.dll
deleting local copy: tprmsrv.dll
deleting local copy: wgaueng1.dll
deleting local copy: wzhjp.dll
deleting local copy: guard.tmp

The following Is the Current Export of the Winlogon notify key:
****************************************************************************
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001


The following are the files found:
****************************************************************************
C:\WINDOWS\system32\aza00cjmefoa0.dll
C:\WINDOWS\system32\Azdiodev.dll
C:\WINDOWS\system32\cartcli.dll
C:\WINDOWS\system32\chgmgr32.dll
C:\WINDOWS\system32\cqgmgr32.dll
C:\WINDOWS\system32\ddrgsnap.dll
C:\WINDOWS\system32\DkvXc32.dll
C:\WINDOWS\system32\dn2401fqe.dll
C:\WINDOWS\system32\dn4m01h1e.dll
C:\WINDOWS\system32\dn8s01l7e.dll
C:\WINDOWS\system32\dpsec.dll
C:\WINDOWS\system32\en0ql1d51.dll
C:\WINDOWS\system32\en46l1hs1.dll
C:\WINDOWS\system32\enrol1931.dll
C:\WINDOWS\system32\f22mlcf11f2.dll
C:\WINDOWS\system32\f2l02c3mgf.dll
C:\WINDOWS\system32\f42m0ef1eh2.dll
C:\WINDOWS\system32\g6040gdqe60e0.dll
C:\WINDOWS\system32\g640lghm164a.dll
C:\WINDOWS\system32\gp00l3dm1.dll
C:\WINDOWS\system32\h04m0ah1ed4.dll
C:\WINDOWS\system32\h4l20e3oeh.dll
C:\WINDOWS\system32\hr2805fue.dll
C:\WINDOWS\system32\hr6s05j7e.dll
C:\WINDOWS\system32\hrl2053oe.dll
C:\WINDOWS\system32\i460lejm1hoa.dll
C:\WINDOWS\system32\i6nmlg5116.dll
C:\WINDOWS\system32\iA60lejm1hoa.dll
C:\WINDOWS\system32\iqign32.dll
C:\WINDOWS\system32\iqmontr.dll
C:\WINDOWS\system32\irj6l51s1.dll
C:\WINDOWS\system32\iymontr.dll
C:\WINDOWS\system32\j8p00i7me8.dll
C:\WINDOWS\system32\jSp00i7me8.dll
C:\WINDOWS\system32\jVvart.dll
C:\WINDOWS\system32\k4pmle711h.dll
C:\WINDOWS\system32\kcdpl.dll
C:\WINDOWS\system32\kjymgr.dll
C:\WINDOWS\system32\kqda1.dll
C:\WINDOWS\system32\l6p2lg7o16.dll
C:\WINDOWS\system32\l88mlil118q.dll
C:\WINDOWS\system32\l8l6li3s18.dll
C:\WINDOWS\system32\liras12n.dll
C:\WINDOWS\system32\LQWEN12N.DLL
C:\WINDOWS\system32\lt4027hmg.dll
C:\WINDOWS\system32\lv0m09d1e.dll
C:\WINDOWS\system32\lv6u09j9e.dll
C:\WINDOWS\system32\lvj8091ue.dll
C:\WINDOWS\system32\m4ls0e37eh.dll
C:\WINDOWS\system32\m6polg7316.dll
C:\WINDOWS\system32\mv06l9ds1.dll
C:\WINDOWS\system32\mv28l9fu1.dll
C:\WINDOWS\system32\mv64l9jq1.dll
C:\WINDOWS\system32\mv80l9lm1.dll
C:\WINDOWS\system32\n22u0cf9ef2.dll
C:\WINDOWS\system32\n26q0cj5efo.dll
C:\WINDOWS\system32\n26qlcj51fo.dll
C:\WINDOWS\system32\n28o0cl3efq.dll
C:\WINDOWS\system32\n6r20g9oe6.dll
C:\WINDOWS\system32\n8n6li5s18.dll
C:\WINDOWS\system32\ndtplwiz.dll
C:\WINDOWS\system32\nflanman.dll
C:\WINDOWS\system32\nvsdexts.dll
C:\WINDOWS\system32\p46s0ej7eho.dll
C:\WINDOWS\system32\q068laju1do8.dll
C:\WINDOWS\system32\q4nule591h.dll
C:\WINDOWS\system32\qvsname.dll
C:\WINDOWS\system32\r28s0cl7efq.dll
C:\WINDOWS\system32\sansapi.dll
C:\WINDOWS\system32\snellstyle.dll
C:\WINDOWS\system32\t2r8lc9u1f.dll
C:\WINDOWS\system32\tprmsrv.dll
C:\WINDOWS\system32\wgaueng1.dll
C:\WINDOWS\system32\wzhjp.dll
C:\WINDOWS\system32\guard.tmp

Registry Entries that were Deleted:
Please verify that the listing looks ok.
If there was something deleted wrongly there are backups in the backreg folder.
****************************************************************************
REGEDIT4

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{20090439-D041-4A68-A8F0-74AEA45FE3F3}"=-
"{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}"=-
"{A77FE05B-AD26-49B9-89E0-501CCAF601FF}"=-
"{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}"=-
[-HKEY_CLASSES_ROOT\CLSID\{20090439-D041-4A68-A8F0-74AEA45FE3F3}]
[-HKEY_CLASSES_ROOT\CLSID\{F7A03849-6E45-461F-A3C6-BDF6E326CA4C}]
[-HKEY_CLASSES_ROOT\CLSID\{A77FE05B-AD26-49B9-89E0-501CCAF601FF}]
[-HKEY_CLASSES_ROOT\CLSID\{1369FBAE-2F4D-4CCF-8ED8-8D5429C5EF7A}]
REGEDIT4

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"SV1"=""
****************************************************************************
Desktop.ini Contents:
****************************************************************************
[.ShellClassInfo]
CLSID={645FF040-5081-101B-9F08-00AA002F954E}
<IDone>{263CE20B-1B20-41CC-9407-9A9B0C05654E}</IDone>
<IDtwo>VT00</IDtwo>
<VERSION>200</VERSION>
****************************************************************************

Quote:
Originally Posted by Hijack This Analyzer
====================================================================
Log was analyzed using KRC HijackThis Analyzer - Updated on 3/2/05
Get updates at http://www.greyknight17.com/download.htm#programs

***Security Programs Detected***

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Logfile of HijackThis v1.99.1
Scan saved at 8:42:33, on 2005/03/27
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\system32\NTMETER.EXE
C:\Smdata\ReadSctService.exe
C:\Program Files\necmfk\necmfk.exe
C:\Program Files\LiquidView\lviewj.exe
C:\WINDOWS\System32\hfsmop.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe
C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
C:\Program Files\子画面設定ユーティリティ\piputil.exe
C:\Program Files\PCGATE Personal\pcgate.exe
C:\Program Files\Opera\opera.exe

O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-gb\msntb.dll
O4 - HKLM\..\Run: [NECMFK] C:\Program Files\necmfk\necmfk.exe
O4 - HKLM\..\Run: [SHRunOnce] C:\Program Files\SmartHobby\SHRunOnce.exe
O4 - HKLM\..\Run: [LiquidView] C:\Program Files\LiquidView\lviewj.exe
O4 - HKLM\..\Run: [HFSMOP] C:\WINDOWS\System32\hfsmop.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-gb\msnappau.exe"
O4 - HKCU\..\Run: [SearchM] C:\Program Files\SmartHobby\PlugIn\CopyFromDigitalCamera\SearchM.exe
O8 - Extra context menu item: BIGLOBE:ニュース検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_news.htm
O8 - Extra context menu item: BIGLOBE:ページ検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_web.htm
O8 - Extra context menu item: BIGLOBE:画像検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_pict.htm
O8 - Extra context menu item: BIGLOBE:辞書検索 - res://C:\Program Files\BIGLOBE\Toolbar\biglobe.dll/script_dic.htm
O9 - Extra 'Tools' menuitem: Sun の Java コンソール - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: JWord(日本語キーワード) - {5D73EE86-05F1-49ed-B850-E423120EC338} - http://www.jword.jp/intro/?partner=A...k&frm=iebutton (file missing)
O11 - Options group: [!CNS] JWord(日本語キーワード)
O14 - IERESET.INF: START_PAGE_URL=http://www.biglobe.ne.jp/
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/sh...3/mcinsctl.cab
O16 - DPF: {665585FD-2068-4C5E-A6D3-53AC3270ECD4} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (ウイルスバスター On-Line Scan) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/sh...20/mcgdmgr.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...n.cab31267.cab
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" --ntservice (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NT Meter - Unknown owner - C:\WINDOWS\system32\NTMETER.EXE
O23 - Service: BroadPass Manager (Poling_Service) - 日本電気株式会社 - c:\Program Files\BIGLOBE\BroadPass\base\base.exe
O23 - Service: ReadSector (ReadSctService) - Unknown owner - C:\Smdata\ReadSctService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


End of KRC HijackThis Analyzer Log.
====================================================================
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-27-2005, 06:02 PM   #16 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

It looks good, but just to make sure:

Go to c:\windows\system32\drivers\etc and open up the hosts file (no extensions) up in Notepad. There should be a bunch of lines with a # in front of them followed by a single line like:

127.0.0.1 localhost

If you have anything after that, please post them here.

If that's ok, then:

Your log is clean. If you disabled System Restore, make sure to enable it now.

To help prevent future spyware installations/infections, please read the Anti-Spyware Tutorial http://www.greyknight17.com/spyware.htm#prevent and use the tools provided.

Are there any problems now? If not, you should be set to go.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-27-2005, 08:36 PM   #17 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Erm...
Quote:
Originally Posted by c:\windows\system32\drivers\etc\hosts
127.0.0.1 www.igetnet.com
127.0.0.1 code.ignphrases.com
127.0.0.1 clear-search.com
127.0.0.1 r1.clrsch.com
127.0.0.1 sds.clrsch.com
127.0.0.1 status.clrsch.com
127.0.0.1 www.clrsch.com
127.0.0.1 clr-sch.com
127.0.0.1 sds-qckads.com
127.0.0.1 status.qckads.com
# Start of entries inserted by Spybot - Search & Destroy
# End of entries inserted by Spybot - Search & Destroy
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
127.0.0.1 status.qckads.com
The weird thing is... I can access the Recycle Bin properly now, which was the only instantly noticable problem...

The only reasons I can think of are...
  • System Restore is still off
  • The computer hasn't been turned off the computer since I first posted the thread, only rebooted
  • I found conime too late
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-27-2005, 09:09 PM   #18 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

I just noticed that it's exactly the same as the hosts log I posted earlier (check post #11). Just before it I I posted...
Quote:
VX2Finder(126): When I clicked "Make Log" nothing noticable happened, so I clicked "Hosts Log" and this came up...
Did something go wrong there?
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-28-2005, 08:13 AM   #19 (permalink)
Analyst, Security Team
 
greyknight17's Avatar
 
Join Date: Jul 2004
Location: New York
Posts: 14,331
OS: Windows 98 & Windows XP Home/Pro

My System

OK, do this again. If VX2Finder doesn't find anything (just one or two lines), then just post that here. We'll see it.

Before doing anything, MAKE SURE that you can keep your computer on (at least until we get it fixed). This infection requires us to detect and remove it without rebooting or restarting your computer (unless the instructions say so). If you can't keep your computer on today, then I suggest that you don't get the logs yet until you are ready. With that said (when ready):

Please download the following programs required for the removal process:

Kill2Me http://www.greyknight17.com/spy/Kill2Me.exe
PV http://www.greyknight17.com/spy/pv.zip
VX2Finder(126) http://www.greyknight17.com/spy/VX2Finder(126).exe
Hoster http://www.greyknight17.com/spy/Hoster.exe
CleanUp! http://cleanup.stevengould.org/ or http://www.greyknight17.com/spy/Cleanup.exe
KillBox http://www.greyknight17.com/spy/KillBox.exe
notify.bat - right click on this link http://www.greyknight17.com/spy/notify.bat and choose Save As...Save it.

Please follow the steps below:

1. Download/run the following uninstallers:

Look2Me Uninstaller http://www.look2me.com/cgi-bin/UnInstaller
IGN Keyword Uninstaller http://www.greyknight17.com/spy/NLNUninstall.zip
ClearSearch Uninstaller http://www.greyknight17.com/spy/ClrSchUninstall.zip

2. Run Kill2Me.

3. Unzip the pv.zip files contents to your Desktop (NOTE: It MUST be on your Desktop!).
a) Open that folder on your Desktop and double click on the runme.bat file.
b) Type in 3 and hit your Enter key. Save the log file.
c) Type in 5 and hit your Enter key. Save the log file.
d) Remember to copy and paste both of these log files in the forum AFTER you are finished with the rest of the steps below.

4. Run notify.bat and it should open up a notify.txt Notepad file. Copy and paste this in the forum later.

5. Run VX2Finder(126) and click on the Find VX2.BetterInternet button. Click Make Log and post this in the forum later.

We also need a list of files in the following folders:

C:\WINDOWS\Downloaded Program Files\ - for these files, if they just have numbers as the filename, right click on them and go to Properties to see what they are. Post the description for each of those here.
C:\Program Files\Internet Explorer\ - there might be a download folder here. We are looking for any randomly named files. Post anything that looks suspicious.

Post all of the logs in your next post. We need them all to get a fix for this infection.
__________________
Please do NOT PM me. Post whatever questions you may have in the forum and we will take a look at it when we get to it. If you have waited for more than 3 days, you may then and ONLY then PM me for assistance. I will take a look at it.

greyknight17 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Old 03-28-2005, 09:51 AM   #20 (permalink)
Registered User
 
Join Date: Mar 2005
Location: London, England
Posts: 70
OS: Windows XP Home

My System

Log 3 was empty...
Quote:
Originally Posted by Log 5
Module information for 'winlogon.exe'
MODULE BASE SIZE PATH
winlogon.exe 1000000 512000 C:\WINDOWS\system32\winlogon.exe 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Logon Application
ntdll.dll 7c940000 643072 C:\WINDOWS\system32\ntdll.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) NT Layer DLL
kernel32.dll 7c800000 1249280 C:\WINDOWS\system32\kernel32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT BASE API Client DLL
ADVAPI32.dll 77d80000 692224 C:\WINDOWS\system32\ADVAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Advanced Windows 32 Base API
RPCRT4.dll 77e30000 593920 C:\WINDOWS\system32\RPCRT4.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Remote Procedure Call Runtime
AUTHZ.dll 77c20000 69632 C:\WINDOWS\system32\AUTHZ.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Authorization Framework
msvcrt.dll 77bc0000 360448 C:\WINDOWS\system32\msvcrt.dll 7.0.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT CRT DLL
CRYPT32.dll 765c0000 602112 C:\WINDOWS\system32\CRYPT32.dll 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Crypto API32
USER32.dll 77cf0000 585728 C:\WINDOWS\system32\USER32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP USER API Client DLL
GDI32.dll 77ed0000 286720 C:\WINDOWS\system32\GDI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) GDI Client DLL
MSASN1.dll 77c40000 73728 C:\WINDOWS\system32\MSASN1.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ASN.1 Runtime APIs
NDdeApi.dll 75880000 32768 C:\WINDOWS\system32\NDdeApi.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Network DDE Share Management APIs
PROFMAP.dll 75870000 40960 C:\WINDOWS\system32\PROFMAP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv
NETAPI32.dll 59250000 344064 C:\WINDOWS\system32\NETAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Net Win32 API DLL
USERENV.dll 759b0000 720896 C:\WINDOWS\system32\USERENV.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Userenv
PSAPI.DLL 76ba0000 45056 C:\WINDOWS\system32\PSAPI.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Process Status Helper
REGAPI.dll 76b70000 61440 C:\WINDOWS\system32\REGAPI.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Registry Configuration APIs
Secur32.dll 77fa0000 69632 C:\WINDOWS\system32\Secur32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Security Support Provider Interface
SETUPAPI.dll 76040000 1413120 C:\WINDOWS\system32\SETUPAPI.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Setup API
VERSION.dll 77bb0000 32768 C:\WINDOWS\system32\VERSION.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Version Checking and File Installation Libraries
WINSTA.dll 762b0000 65536 C:\WINDOWS\system32\WINSTA.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Winstation Library
WINTRUST.dll 76be0000 188416 C:\WINDOWS\system32\WINTRUST.dll 5.131.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Trust Verification APIs
IMAGEHLP.dll 76c40000 163840 C:\WINDOWS\system32\IMAGEHLP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Image Helper
WS2_32.dll 719e0000 94208 C:\WINDOWS\system32\WS2_32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 32-Bit DLL
WS2HELP.dll 719d0000 32768 C:\WINDOWS\system32\WS2HELP.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Socket 2.0 Helper for Windows NT
IMM32.DLL 762e0000 118784 C:\WINDOWS\system32\IMM32.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows XP IMM32 API Client DLL
LPK.DLL 60740000 36864 C:\WINDOWS\system32\LPK.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Language Pack
USP10.dll 73f80000 438272 C:\WINDOWS\system32\USP10.dll 1.0420.2600.2180 (xpsp_sp2_rtm.040803-2158) Uniscribe Unicode script processor
MSGINA.dll 758b0000 995328 C:\WINDOWS\system32\MSGINA.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT Logon GINA DLL
SHELL32.dll 77380000 8376320 C:\WINDOWS\system32\SHELL32.dll 6.00.2900.2578 (xpsp_sp2_gdr.041130-1729) Windows Shell Common Dll
SHLWAPI.dll 77f20000 483328 C:\WINDOWS\system32\SHLWAPI.dll 6.00.2900.2573 (xpsp_sp2_gdr.041130-1729) Shell Light-weight Utility Library
COMCTL32.dll 5ab60000 618496 C:\WINDOWS\system32\COMCTL32.dll 5.82 (xpsp_sp2_rtm.040803-2158) Common Controls Library
ODBC32.dll 73520000 249856 C:\WINDOWS\system32\ODBC32.dll 3.525.1117.0 (xpsp_sp2_rtm.040803-2158) Microsoft Data Access - ODBC Driver Manager
comdlg32.dll 76300000 294912 C:\WINDOWS\system32\comdlg32.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Common Dialogs DLL
comctl32.dll 77160000 1056768 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll 6.0 (xpsp_sp2_rtm.040803-2158) User Experience Controls Library
odbcint.dll 20000000 94208 C:\WINDOWS\system32\odbcint.dll 3.525.1117.0 built by: (_sqlbld) Microsoft Data Access - ODBC Resources
SHSVCS.dll 76df0000 143360 C:\WINDOWS\system32\SHSVCS.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Windows Shell Services Dll
sfc.dll 76b60000 20480 C:\WINDOWS\system32\sfc.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows File Protection
sfc_os.dll 76c10000 167936 C:\WINDOWS\system32\sfc_os.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows File Protection
ole32.dll 76970000 1298432 C:\WINDOWS\system32\ole32.dll 5.1.2600.2595 (xpsp_sp2_gdr.041130-1729) Microsoft OLE for Windows
Apphelp.dll 76d90000 139264 C:\WINDOWS\system32\Apphelp.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Application Compatibility Client Library
msctfime.ime 73620000 188416 C:\WINDOWS\system32\msctfime.ime 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Text Frame Work Service IME
uxtheme.dll 58730000 229376 C:\WINDOWS\system32\uxtheme.dll 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) Microsoft UxTheme Library
sxs.dll 75de0000 716800 C:\WINDOWS\system32\sxs.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Fusion 2.5
WINSCARD.DLL 72340000 110592 C:\WINDOWS\system32\WINSCARD.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Smart Card API
WTSAPI32.dll 76f00000 32768 C:\WINDOWS\system32\WTSAPI32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Terminal Server SDK APIs
WINMM.dll 76af0000 176128 C:\WINDOWS\system32\WINMM.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) MCI API DLL
SYNCOR11.DLL 6bd00000 53248 C:\WINDOWS\system32\SYNCOR11.DLL 1.2.3 SynthCore R2.0 Midi Interface Driver
cscdll.dll 76550000 114688 C:\WINDOWS\system32\cscdll.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Offline Network Agent
WlNotify.dll 75890000 106496 C:\WINDOWS\system32\WlNotify.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Common DLL to receive Winlogon notifications
WINSPOOL.DRV 72f50000 155648 C:\WINDOWS\system32\WINSPOOL.DRV 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows Spooler Driver
MPR.dll 71a50000 73728 C:\WINDOWS\system32\MPR.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Multiple Provider Router DLL
rsaenh.dll ffd0000 163840 C:\WINDOWS\system32\rsaenh.dll 5.1.2600.2161 (xpsp.040706-1629) Microsoft Enhanced Cryptographic Provider
SAMLIB.dll 71b40000 77824 C:\WINDOWS\system32\SAMLIB.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) SAM Library DLL
msv1_0.dll 77cb0000 143360 C:\WINDOWS\system32\msv1_0.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft Authentication Package v1.0
iphlpapi.dll 76d10000 102400 C:\WINDOWS\system32\iphlpapi.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) IP Helper API
imjp81.ime 4edc0000 352256 C:\WINDOWS\system32\imjp81.ime 8.1.4202.0 Microsoft IME Standard
imjp81k.dll 648f0000 851968 C:\WINDOWS\system32\imjp81k.dll 8.1.4202.0 Microsoft IME
cscui.dll 76570000 327680 C:\WINDOWS\system32\cscui.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Client Side Caching UI
xpsp2res.dll 1900000 5636096 C:\WINDOWS\system32\xpsp2res.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Service Pack 2 Messages
NTMARTA.DLL 76c90000 131072 C:\WINDOWS\system32\NTMARTA.DLL 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Windows NT MARTA provider
WLDAP32.dll 76f10000 180224 C:\WINDOWS\system32\WLDAP32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Win32 LDAP API DLL
IMJPCD.DIC 3b100000 110592 C:\WINDOWS\IME\IMJP8_1\Dicts\IMJPCD.DIC 8.1.4202.0 Microsoft IME Code Dictionary
wdmaud.drv 72c70000 36864 C:\WINDOWS\system32\wdmaud.drv 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) WDM Audio driver mapper
msacm32.drv 72c60000 32768 C:\WINDOWS\system32\msacm32.drv 5.1.2600.0 (xpclient.010817-1148) Microsoft Sound Mapper
MSACM32.dll 77b90000 86016 C:\WINDOWS\system32\MSACM32.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft ACM Audio Filter
midimap.dll 77b80000 28672 C:\WINDOWS\system32\midimap.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) Microsoft MIDI Mapper
COMRes.dll 77000000 700416 C:\WINDOWS\system32\COMRes.dll 2001.12.4414.258
OLEAUT32.dll 770d0000 573440 C:\WINDOWS\system32\OLEAUT32.dll 5.1.2600.2180
CLBCATQ.DLL 76f80000 520192 C:\WINDOWS\system32\CLBCATQ.DLL 2001.12.4414.258
Cabinet.dll 75090000 81920 C:\WINDOWS\system32\Cabinet.dll 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) MicrosoftR Cabinet File API
Quote:
Originally Posted by Notify
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
6c,00,00,00
"Logoff"="ChainWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
"Asynchronous"=dword:00000000
"Impersonate"=dword:00000000
"DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Logoff"="CryptnetWlxLogoffEvent"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
"DLLName"="cscdll.dll"
"Logon"="WinlogonLogonEvent"
"Logoff"="WinlogonLogoffEvent"
"ScreenSaver"="WinlogonScreenSaverEvent"
"Startup"="WinlogonStartupEvent"
"Shutdown"="WinlogonShutdownEvent"
"StartShell"="WinlogonStartShellEvent"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
"DLLName"="wlnotify.dll"
"Logon"="SCardStartCertProp"
"Logoff"="SCardStopCertProp"
"Lock"="SCardSuspendCertProp"
"Unlock"="SCardResumeCertProp"
"Enabled"=dword:00000001
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"StartShell"="SchedStartShell"
"Logoff"="SchedEventLogOff"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
"Logoff"="WLEventLogoff"
"Impersonate"=dword:00000000
"Asynchronous"=dword:00000001
"DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
"DLLName"="WlNotify.dll"
"Lock"="SensLockEvent"
"Logon"="SensLogonEvent"
"Logoff"="SensLogoffEvent"
"Safe"=dword:00000001
"MaxWait"=dword:00000258
"StartScreenSaver"="SensStartScreenSaverEvent"
"StopScreenSaver"="SensStopScreenSaverEvent"
"Startup"="SensStartupEvent"
"Shutdown"="SensShutdownEvent"
"StartShell"="SensStartShellEvent"
"PostShell"="SensPostShellEvent"
"Disconnect"="SensDisconnectEvent"
"Reconnect"="SensReconnectEvent"
"Unlock"="SensUnlockEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
"Asynchronous"=dword:00000000
"DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
6c,00,6c,00,00,00
"Impersonate"=dword:00000000
"Logoff"="TSEventLogoff"
"Logon"="TSEventLogon"
"PostShell"="TSEventPostShell"
"Shutdown"="TSEventShutdown"
"StartShell"="TSEventStartShell"
"Startup"="TSEventStartup"
"MaxWait"=dword:00000258
"Reconnect"="TSEventReconnect"
"Disconnect"="TSEventDisconnect"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
"DLLName"="wlnotify.dll"
"Logon"="RegisterTicketExpiredNotificationEvent"
"Logoff"="UnregisterTicketExpiredNotificationEvent"
"Impersonate"=dword:00000001
"Asynchronous"=dword:00000001
Still no actual file made for VX2, but this was the closest thing without clicking "Hosts Log"... It came up as the scan ended.
Quote:
Files Found---

Additional Files---

Keys Under Notify---crypt32chain
Keys Under Notify---cryptnet
Keys Under Notify---cscdll
Keys Under Notify---ScCertProp
Keys Under Notify---Schedule
Keys Under Notify---sclgntfy
Keys Under Notify---SensLogn
Keys Under Notify---termsrv
Keys Under Notify---wlballoon


Guardian Key--- is called:

User Agent String---
SV1
Is this what you were looking for?


The rest is exactly the same as before...

Downloaded Program Files (Description in brackets):

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21}
{BCC0FF27-31D9-4614-A68E-C18E1ADA4389}
FileSharingCtrl Class (fsmsngr Module)
Java Runtime Environment 1.4.2
Java Runtime Environment 1.4.2
MessengerStatsClient Class
MsnMessengerSetupDownloadControl Class
Solitaire Showdown Class
ウイルスバスター On-line Scan

The first two didn't have a description, but on the first tab the piece of information above the (install?) date was (ActiveX コントロール) the last word means "control" in Japanese. The On-Line Scan one I think says something like Wills Buster. It's the first word I'm not sure of...

C:\Program Files\Internet Explorer\
Folders
  • Connection Wizard
  • Custom
  • mui
  • PLUGINS
  • SIGNUP
dll files
  • hmmapi.dll
Applications
  • iedw (Apparantly it's Crash Detection)
  • iexplore (Internet Explorer)
Crypto Shell Extensions
  • KB870669
  • Q330994
  • Q818529
  • Q822925
  • Q823353
  • Q831167
Zeokage is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
 


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 04:21 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85