arnoldkc
2006-10-22, 09:01
Fixwareout ver 1.003
Last edited 8/11/2006
Post this report in the forums please
Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E0132CE0603-B6F8-3D64-74CE-5C983602{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\femmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1trap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\2trap
...
Microsoft (R) Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmmef.exe"=-
...
PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»» Searching by size/names...
* csr.exe C:\WINDOWS\System32\CSEII.EXE
* csr.exe C:\WINDOWS\System32\{BDD2B~1.EXE
»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSEII.EXE 51,233 2006-08-30
C:\WINDOWS\SYSTEM32\DMIFE.EXE 61,985 2004-08-09
C:\WINDOWS\SYSTEM32\DMMEF.EXE 61,985 2004-08-09
C:\WINDOWS\SYSTEM32\DMXXI.EXE 61,985 2004-08-09
Other suspects.
Directory of C:\WINDOWS\system32
{BDD2BCD6-BE9F-46B8-9BA4-D9E9540BBD95}.exe
»»»»» Misc files.
»»»»» Checking for older varients covered by the Rem3 tool.
Last edited 8/11/2006
Post this report in the forums please
Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\}8E0132CE0603-B6F8-3D64-74CE-5C983602{
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\femmd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\1trap
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\2trap
...
Microsoft (R) Windows Script Host Version 5.6
Random Runs removed from HKLM
"dmmef.exe"=-
...
PLEASE NOTE, There WILL be LEGITIMATE FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
»»»»» Searching by size/names...
* csr.exe C:\WINDOWS\System32\CSEII.EXE
* csr.exe C:\WINDOWS\System32\{BDD2B~1.EXE
»»»»»
Search five digit cs, dm and jb files.
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSEII.EXE 51,233 2006-08-30
C:\WINDOWS\SYSTEM32\DMIFE.EXE 61,985 2004-08-09
C:\WINDOWS\SYSTEM32\DMMEF.EXE 61,985 2004-08-09
C:\WINDOWS\SYSTEM32\DMXXI.EXE 61,985 2004-08-09
Other suspects.
Directory of C:\WINDOWS\system32
{BDD2BCD6-BE9F-46B8-9BA4-D9E9540BBD95}.exe
»»»»» Misc files.
»»»»» Checking for older varients covered by the Rem3 tool.